Best Web Application Firewalls (WAF)

How Many Web Application Firewalls (WAF) Products Does G2 Track?

Total Products under this Category: 92

Category Stats (Aug 2026)

  • Average Rating: 4.45/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Radware Cloud WAF (+0.17%) - Among all products in this category, Radware Cloud WAF recorded the largest rating increase compared to last month

Last updated: August 05, 2026

How Does G2 Rank Web Application Firewalls (WAF) Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,300+ Authentic Reviews
  • 92+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Web Application Firewalls (WAF)

G2 Grid® for Web Application Firewalls (WAF) plotting products by satisfaction and market presence

Highlighted products: Cloudflare Application Security and Performance, Radware Cloud WAF, Check Point WAF (formerly CloudGuard WAF), HAProxy, FortiAppSec Cloud, Fastly's Web Application and API Security, Azion, and AWS WAF.

Underlying data: [Grid® JSON](https://www.g2.com/categories/web-application-firewall-waf/grids.json?focus%5B%5D=cloudflare-application-security-and-performance&focus%5B%5D=radware-cloud-waf&focus%5B%5D=check-point-waf-formerly-cloudguard-waf&focus%5B%5D=haproxy&focus%5B%5D=fortiappsec-cloud&focus%5B%5D=fastly-s-web-application-and-api-security&focus%5B%5D=azion&focus%5B%5D=aws-waf)

Sponsored

Fortinet Managed Rules for AWS WAF

Fortinet’s WAF rulesets are additional security signatures that can be used to enhance the protections included in the base AWS WAF product. They are updated on a regular basis to include the latest threat intelligence from the award-winning FortiGuard Labs. The Complete OWASP Top 10 Ruleset provides a comprehensive package for web application protection offered by Fortinet to help address the OWASP Top 10 web application threats. Includes protection for various Injection attacks such as SQL and command Injection , Cross Site Scripting, General and Known Exploits, Malicious Bots and Common Vulnerabilities and Exposures (CVE).

Visit website

Cloudflare Application Security and Performance

Cloudflare is the connectivity cloud for the "everywhere world," on a mission to help build a better Internet. We provide a unified platform of networking, security, and developer services delivered from a single, intelligent global network that spans hundreds of cities in over 125 countries. This empowers organizations of all sizes, from small businesses to the world's largest enterprises, to make their employees, applications, and networks faster and more secure everywhere, while significantly reducing complexity and cost. Our comprehensive platform includes: - Advanced Security: Protect your online presence with industry-leading DDoS protection, a robust Web Application Firewall (WAF), Bot mitigation, and API security. Implement Zero Trust security to secure remote access, data, and applications for your entire workforce. - Superior Performance: Accelerate website and application loading times globally with our Content Delivery Network (CDN), intelligent DNS, and smart routing capabilities. Optimize images and deliver dynamic content with unparalleled speed. - Powerful Developer Tools: Empower your developers to build and deploy full-stack applications at the edge using Cloudflare Workers (serverless functions), R2 Storage (object storage without egress fees), and D1 (serverless SQL database). Cloudflare helps connect and protect millions of customers globally, offering the control, visibility, and reliability businesses need to work, develop, and accelerate their operations in today's hyperconnected landscape. Our global network continuously learns and adapts, ensuring your digital assets are always protected and performing at their best.

Average Rating: 4.5/5.0

Total Reviews: 678

How Do G2 Users Rate Cloudflare Application Security and Performance?

  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 8.7/10)
  • Traffic Controls: 9.0/10 (Category avg: 9.1/10)
  • Security Monitoring: 9.1/10 (Category avg: 9.1/10)
  • Issue Tracking: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind Cloudflare Application Security and Performance?

  • Seller: Cloudflare, Inc.
  • Company Website:
  • Year Founded: 2009
  • HQ Location: San Francisco, California
  • Twitter: @Cloudflare
    286,254 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    7,190 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Web Developer, Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 61% Small, 27% Medium

What Do G2 Reviewers Say About Cloudflare Application Security and Performance?

AI-generated summary from verified user reviews

Pros
  • Users commend Cloudflare for its robust security features, including automatic DDoS protection and a helpful Web Application Firewall.
  • Users appreciate the ease of use of Cloudflare, with an intuitive dashboard simplifying security and performance management.
  • Users appreciate the user-friendly interface and comprehensive features of Cloudflare, streamlining security and performance management.
  • Users commend the enhanced performance of Cloudflare, noting faster page loads and seamless integration for website security.
  • Users value the effective DDoS protection from Cloudflare, ensuring peace of mind with enhanced application security.
Cons
  • Users find the complex user interface challenging, especially when navigating advanced features and configurations effectively.
  • Users find the platform expensive, especially as many useful features require upgrading to higher-priced plans.
  • Users experience a complex setup requiring extra time, making it less friendly for those unfamiliar with security configurations.
  • Users find the complexity of advanced configurations challenging, especially for those new to security platforms.
  • Users note a steep learning curve for advanced features, which can complicate their overall experience with Cloudflare.

What Are Recent G2 Reviews of Cloudflare Application Security and Performance?

What Are G2 Users Discussing About Cloudflare Application Security and Performance?

Radware Cloud WAF

Radware Cloud WAF is a fully managed Cloud Application Protection Service providing the industry's most comprehensive web application security solution. The service integrates Radware's Cloud WAF, API Protection, Bot management, client-side and application layer DDoS protection in a single portal that provides security analytics, threat detection and real-time security feeds to protect applications against hacking, malicious bots, API exposure, Web DDoS attacks, supply chain attacks and other vulnerabilities.

Average Rating: 4.6/5.0

Total Reviews: 142

How Do G2 Users Rate Radware Cloud WAF?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.7/10)
  • Traffic Controls: 9.2/10 (Category avg: 9.1/10)
  • Security Monitoring: 9.3/10 (Category avg: 9.1/10)
  • Issue Tracking: 8.8/10 (Category avg: 8.7/10)

Who Is the Company Behind Radware Cloud WAF?

  • Seller: Radware
  • Company Website:
  • Year Founded: 1997
  • HQ Location: Tel Aviv, Tel Aviv
  • Twitter: @radware
    12,488 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,602 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 46% Medium, 42% Large

What Do G2 Reviewers Say About Radware Cloud WAF?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the dynamic protection and security features of Radware Cloud WAF, ensuring robust safety for web applications.
  • Users value the strong AI-driven protection of Radware Cloud WAF, ensuring reliable security with minimal performance impact.
  • Users appreciate Radware Cloud WAF for its advanced cybersecurity features and impressive automated protection capabilities.
  • Users commend Radware Cloud WAF for its effective DDoS protection, ensuring performance stability during attacks.
  • Users value the real-time monitoring capabilities of Radware Cloud WAF, ensuring effective and prompt threat detection.
Cons
  • Users find difficult reporting with Radware Cloud WAF, feeling it lacks clarity and flexibility for effective insights.
  • Users often find the learning difficulty of Radware Cloud WAF to be a significant barrier to effective use.
  • Users find complex configuration requirements challenging, needing extensive understanding and time for effective optimization.
  • Users feel the limited customization options hinder the ability to tailor Radware Cloud WAF to specific needs.
  • Users find the user interface complicated, noting issues with intuitiveness, advanced features, and reporting flexibility.

What Are Recent G2 Reviews of Radware Cloud WAF?

What Are G2 Users Discussing About Radware Cloud WAF?

Check Point WAF (formerly CloudGuard WAF)

CloudGuard WAF est une solution de sécurité Web et API native du cloud conçue pour aider les utilisateurs à protéger leurs applications contre les menaces connues et inconnues. En exploitant une IA contextuelle avancée, cette solution offre une prévention précise des menaces sans avoir besoin de méthodes de détection basées sur des signatures traditionnelles. Cette approche innovante permet aux organisations de maintenir une posture de sécurité robuste tout en minimisant les risques associés aux menaces cybernétiques en évolution. Principalement ciblé sur les entreprises qui dépendent des applications Web et des API, CloudGuard WAF est particulièrement bénéfique pour les entreprises dans des secteurs tels que la finance, la santé et le commerce électronique, où la protection des données est primordiale. La solution est conçue pour répondre aux défis de sécurité complexes qui surviennent dans les environnements d'application modernes, en particulier ceux utilisant des pratiques d'intégration et de déploiement continus (CI/CD). À mesure que les organisations adoptent de plus en plus des architectures natives du cloud, le besoin de solutions de sécurité flexibles et efficaces devient critique. L'une des caractéristiques remarquables de CloudGuard WAF est ses capacités de protection préventive. En employant des mesures de sécurité basées sur l'apprentissage automatique, la solution peut efficacement prévenir les menaces de type zero-day, qui sont des vulnérabilités qui n'ont pas encore été découvertes ou corrigées. Cette approche proactive élimine la dépendance aux mises à jour fréquentes de signatures, permettant aux organisations de rester en avance sur les attaques potentielles sans avoir besoin d'une intervention manuelle constante. De plus, CloudGuard WAF excelle dans la détection précise, lui permettant d'identifier une gamme plus large d'attaques tout en minimisant le besoin de réglages continus et de création d'exceptions. Cette fonctionnalité améliore non seulement la précision de la détection des menaces, mais réduit également la charge opérationnelle des équipes de sécurité, leur permettant de se concentrer sur des initiatives plus stratégiques plutôt que sur des ajustements de routine. Conçu avec des principes natifs du cloud à l'esprit, CloudGuard WAF prend en charge le déploiement et l'automatisation compatibles CI/CD. Cela signifie que les organisations peuvent facilement intégrer la solution dans leurs flux de travail existants, de l'installation aux mises à jour et à la configuration. En utilisant une infrastructure déclarative en tant que code ou des API, les utilisateurs peuvent rationaliser leurs processus de sécurité, garantissant que leurs applications restent protégées à mesure qu'elles évoluent. Dans l'ensemble, CloudGuard WAF représente une avancée significative dans le domaine de la sécurité Web et API, offrant aux organisations une solution sophistiquée et adaptable pour lutter contre le paysage en constante évolution des menaces cybernétiques. Sa combinaison de protection préventive, de détection précise et de conception native du cloud en fait un atout précieux pour toute organisation cherchant à améliorer sa posture de sécurité dans l'environnement numérique d'aujourd'hui.

Average Rating: 4.4/5.0

Total Reviews: 88

How Do G2 Users Rate Check Point WAF (formerly CloudGuard WAF)?

  • the product a-t-il été un bon partenaire commercial?: 8.6/10 (Category avg: 8.7/10)
  • Contrôles de la circulation: 8.7/10 (Category avg: 9.1/10)
  • Surveillance de la sécurité: 9.3/10 (Category avg: 9.1/10)
  • Suivi des problèmes: 8.6/10 (Category avg: 8.7/10)

Who Is the Company Behind Check Point WAF (formerly CloudGuard WAF)?

  • Vendeur: Check Point Software Technologies
  • Site Web de l'entreprise:
  • Année de fondation: 1993
  • Emplacement du siège social: Redwood City, CA
  • Twitter: @CheckPointSW
    70,955 abonnés Twitter
  • Page LinkedIn®: www.linkedin.com
    8,554 employés sur LinkedIn®

Who Uses This Product?

  • Who Uses This: Ingénieur logiciel
  • Top Industries: Technologie de l'information et services, Sécurité informatique et réseau
  • Company Size: 58% Medium, 27% Small

What Do G2 Reviewers Say About Check Point WAF (formerly CloudGuard WAF)?

AI-generated summary from verified user reviews

Pros
  • Les utilisateurs soulignent les fonctionnalités de sécurité fiables de Check Point WAF, assurant une protection efficace contre les attaques web sans effort.
  • Les utilisateurs apprécient les fonctionnalités de sécurité robustes de Check Point CloudGuard WAF, permettant une protection personnalisée avec un effort de gestion minimal.
  • Les utilisateurs apprécient l'IA contextuelle de Check Point CloudGuard WAF, offrant une protection efficace avec un minimum de faux positifs.
  • Les utilisateurs apprécient la protection DDoS robuste de Check Point CloudGuard WAF, garantissant la sécurité des applications cloud et du trafic API.
  • Les utilisateurs apprécient Check Point WAF pour sa protection complète contre les attaques web et son intégration transparente avec les environnements cloud.
Cons
  • Les utilisateurs trouvent la configuration complexe difficile, en particulier pour les équipes nouvelles dans l'écosystème de Check Point.
  • Les utilisateurs trouvent que le WAF de Check Point est cher, surtout par rapport aux concurrents malgré ses fonctionnalités avancées.
  • Les utilisateurs trouvent la difficulté d'apprentissage difficile en raison de la configuration complexe et des exigences de configuration étendues.
  • Les utilisateurs font face à une courbe d'apprentissage difficile en raison des nombreuses fonctionnalités et configurations requises pour une utilisation efficace.
  • Les utilisateurs trouvent souvent l'interface utilisateur accablante, en particulier lors de la configuration initiale et lors de la navigation dans des fonctionnalités complexes.

What Are Recent G2 Reviews of Check Point WAF (formerly CloudGuard WAF)?

HAProxy

HAProxy is an open-source software load balancer and reverse proxy for TCP, QUIC, and HTTP-based applications. It provides high availability, load balancing, and best-in-class SSL processing. HAProxy One is an application delivery and security platform that combines the HAProxy core with enterprise-grade security layers, management and orchestration, cloud-native integration, and more. Platform components: HAProxy Enterprise: a flexible data plane layer for TCP, UDP, QUIC, and HTTP-based applications that provides high-performance load balancing, high availability, an API/AI gateway, container networking, SSL processing, DDoS protection, bot detection and mitigation, global rate limiting, and a web application firewall (WAF). HAProxy Fusion: a scalable control plane that provides full-lifecycle management, observability, and automation of multi-cluster, multi-cloud, and multi-team HAProxy Enterprise deployments, with infrastructure integration for AWS, Kubernetes, Consul, and Prometheus. HAProxy Edge: a globally distributed application delivery network that provides fully managed application delivery and security services, a secure partition between external traffic and origin networks, and threat intelligence enhanced by machine learning that powers the security layers in HAProxy Fusion and HAProxy Enterprise. Learn more at HAProxy.com

Average Rating: 4.7/5.0

Total Reviews: 904

How Do G2 Users Rate HAProxy?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 8.7/10)
  • Traffic Controls: 9.0/10 (Category avg: 9.1/10)
  • Security Monitoring: 8.3/10 (Category avg: 9.1/10)
  • Issue Tracking: 8.2/10 (Category avg: 8.7/10)

Who Is the Company Behind HAProxy?

  • Seller: HAProxy
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Newton, MA
  • Twitter: @HAProxy
    21,218 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    125 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: DevOps Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 42% Medium, 35% Large

What Do G2 Reviewers Say About HAProxy?

AI-generated summary from verified user reviews

Pros
  • Users find HAProxy incredibly easy to use, with intuitive configuration and helpful overview stats for services.
  • Users appreciate the ease of implementation and effective workload balancing offered by HAProxy for load management.
  • Users value HAProxy for its reliability and speed, ensuring secure and efficient data transmission for websites.
  • Users value the high performance of HAProxy, enabling secure and efficient data transmission for various applications.
  • Users appreciate the easy configuration of HAProxy, enabling efficient traffic management and seamless operation.
Cons
  • Users find the difficult configuration of HAProxy challenging, with complex syntax and hard-to-read files.
  • Users find the steep learning curve of HAProxy challenging, particularly for beginners and complex configurations.
  • Users find the complex setup of HAProxy challenging, particularly for those unfamiliar with advanced configurations.
  • Users find the complex configuration of HAProxy challenging, particularly for newcomers and larger setups.
  • Users find the complexity of HAProxy's configuration challenging, making advanced setups cumbersome and time-consuming to manage.

What Are Recent G2 Reviews of HAProxy?

What Are G2 Users Discussing About HAProxy?

Fastly's Web Application and API Security

Fastly’s AppSec solutions empower teams to mitigate threats and control bots while helping the business move faster, confidently. Protect Your Apps and APIs While Accelerating Growth with Fastly’s Next-Gen WAF, DDoS Protection, Bot Management, API Security, and more. Our solutions are designed to help you stop cyber threats from derailing your biggest moments, accelerate innovation while minimizing new risk, and govern bots without increasing user friction.

Average Rating: 4.2/5.0

Total Reviews: 29

How Do G2 Users Rate Fastly's Web Application and API Security?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 8.7/10)
  • Traffic Controls: 8.1/10 (Category avg: 9.1/10)
  • Security Monitoring: 9.1/10 (Category avg: 9.1/10)
  • Issue Tracking: 8.1/10 (Category avg: 8.7/10)

Who Is the Company Behind Fastly's Web Application and API Security?

  • Seller: Fastly
  • Year Founded: 2011
  • HQ Location: San Francisco, California, United States
  • Twitter: @Fastly
    29,199 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,398 employees on LinkedIn®
  • Ownership: NYSE: FSLY

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 50% Medium, 37% Large

What Do G2 Reviewers Say About Fastly's Web Application and API Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of setup and implementation of Fastly's Web Application and API Security, enhancing their experience.
  • Users appreciate the robust security features of Fastly's Web Application and API Security, ensuring comprehensive protection.
  • Users commend the exceptional customer support from Fastly, facilitating easy implementation and quick assistance for development teams.
  • Users commend Fastly's Web Application and API Security for its exceptional DDoS protection and effective threat mitigation capabilities.
  • Users value the robust protection Fastly's Web Application and API Security offers against various application attacks.
Cons
  • Users find the pricing to be high, especially for small projects and additional tech support needs.
  • Users express frustration with poor customer support, often facing delays and inadequate assistance when needing help.
  • Users find the complex configuration of Fastly's Web Application and API Security time-consuming and challenging to navigate.
  • Users find the complex setup of Fastly's Web Application and API Security to be time-consuming and challenging.
  • Users find the complex management of Fastly's Web Application and API Security challenging, affecting setup and rule navigation.

What Are Recent G2 Reviews of Fastly's Web Application and API Security?

FortiAppSec Cloud

FortiAppSec Cloud - the next evolution of FortiWeb Cloud - simplifies and strengthens web application security and delivery across your cloud environments. This SaaS platform secures network availability and accelerates application performance while delivering consistent security against web-based threats. The AI-driven engine detects zero-day exploits and unknown threats, maximizing detection accuracy while securing the user experience and minimizing false positives. FortiAppSec Cloud is unified platform that provides comprehensive web application and API protection (WAAP) with a single management interface. It includes: • GenAI-ready protection for known and zero-day threat detection • ML-driven bad bot behavioral analysis to fend off sophisticated bots • Advanced API discovery and security • Built-in DAST allows for vulnerability scanning and patching in advance • Global server load balancing and CDN provide optimized application availability and performance. • Threat analytics helps prioritize security events for operational efficiency.

Average Rating: 4.4/5.0

Total Reviews: 29

How Do G2 Users Rate FortiAppSec Cloud?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 8.7/10)
  • Traffic Controls: 8.2/10 (Category avg: 9.1/10)
  • Security Monitoring: 9.2/10 (Category avg: 9.1/10)
  • Issue Tracking: 7.9/10 (Category avg: 8.7/10)

Who Is the Company Behind FortiAppSec Cloud?

  • Seller: Fortinet
  • Company Website:
  • Year Founded: 2000
  • HQ Location: Sunnyvale, CA
  • Twitter: @Fortinet
    151,422 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16,279 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 61% Medium, 19% Large

What Do G2 Reviewers Say About FortiAppSec Cloud?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the robust security features of FortiAppSec Cloud, providing excellent protection against evolving threats.
  • Users appreciate the automatic security and centralized dashboard of FortiAppSec Cloud, enhancing visibility and response times.
  • Users appreciate the robust cybersecurity features of FortiAppSec Cloud, effectively addressing modern security threats.
  • Users highlight the ease of use of FortiAppSec Cloud, benefiting from its straightforward setup and user-friendly interface.
  • Users appreciate the ease of deployment and AI-powered automation in FortiAppSec Cloud for enhanced web app protection.
Cons
  • Users find the UX lacking in intuitiveness, making the setup and customization process frustratingly complicated.
  • Users experience slow performance during high traffic, leading to latency and lag in security responses.
  • Users find the user interface issues hinder overall usability, suggesting improvements for a more intuitive experience.
  • Users face a complex configuration process with FortiAppSec Cloud, making initial setup challenging, especially for newcomers.
  • Users find the complex setup of FortiAppSec Cloud challenging, especially for first-time users and advanced policies.

What Are Recent G2 Reviews of FortiAppSec Cloud?

What Are G2 Users Discussing About FortiAppSec Cloud?

Azion

Azion is the web platform that enables businesses to build, secure, and scale modern applications on a fully managed global infrastructure, with a robust suite of solutions for Application Development, cybersecurity, and AI. Azion allows developers to deploy applications closer to users, ensuring ultra-low latency and high availability. With Functions, you can run distributed serverless code, enhancing performance and reducing costs. For enhanced security, Azion’s Web Application Firewall (WAF) protects against cyber threats. Azion also provides SQL Storage, Object Storage and KV Storage, enabling fast, distributed data storage and retrieval. With Real-Time Metrics and Real-Time Events, businesses gain actionable insights into their applications and infrastructure, ensuring optimal performance and security. Global leaders like Prime Video, Neon, Global Fashion Group, and Radware trust Azion to deliver high-performance, secure digital experiences worldwide. Whether you're building AI-driven applications, securing your digital assets, or scaling globally, Azion provides the fastest path to modern applications. Discover how Azion can transform your digital experiences and empower your business to thrive in the digital age. Visit www.azion.com to learn more about our innovative solutions.

Average Rating: 4.7/5.0

Total Reviews: 31

How Do G2 Users Rate Azion?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 8.7/10)
  • Traffic Controls: 9.6/10 (Category avg: 9.1/10)
  • Security Monitoring: 9.3/10 (Category avg: 9.1/10)
  • Issue Tracking: 9.1/10 (Category avg: 8.7/10)

Who Is the Company Behind Azion?

  • Seller: Azion
  • Year Founded: 2011
  • HQ Location: Palo Alto, California, United States
  • LinkedIn® Page: www.linkedin.com
    198 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Retail
  • Company Size: 34% Large, 28% Medium

What Do G2 Reviewers Say About Azion?

AI-generated summary from verified user reviews

Pros
  • Users praise Azion for its responsive and knowledgeable customer support, ensuring smooth and efficient operations.
  • Users find Azion to be easy to use and integrate, enhancing daily operations with minimal effort.
  • Users find easy integrations with Azion to be seamless, enhancing their operational workflows and efficiency.
  • Users commend Azion's reliability, consistently meeting expectations with excellent service and robust performance during high traffic periods.
  • Users commend Azion for its exceptional performance and reliability, leading to improved user experience and business continuity.
Cons
  • Users are frustrated with Azion's missing features for Web3 and other essential integrations, impacting their workflow.
  • Users find the complexity of the administration console challenging, requiring time to fully understand its features.
  • Users find the difficult learning curve with Azion's administration console features frustrating and time-consuming.
  • Users find the difficult learning curve of Azion challenging due to the unintuitive features in the administration console.
  • Users desire more flexibility in pricing for Azion, indicating that it's currently considered expensive.

What Are Recent G2 Reviews of Azion?

AWS WAF

AWS WAF (Web Application Firewall) est un service de sécurité conçu pour protéger les applications web et les API contre les exploits web courants et les bots qui peuvent compromettre la sécurité, affecter la disponibilité ou consommer des ressources excessives. En permettant aux utilisateurs de définir des règles de sécurité web personnalisables, AWS WAF offre un contrôle précis sur le trafic à autoriser ou à bloquer, garantissant une protection robuste adaptée aux besoins spécifiques des applications. Caractéristiques clés et fonctionnalités : - Règles de sécurité personnalisables : Les utilisateurs peuvent créer des règles pour filtrer les requêtes web en fonction de conditions telles que les adresses IP, les en-têtes HTTP, le corps HTTP ou les URI personnalisés, permettant des mesures de sécurité sur mesure. - Groupes de règles gérés : AWS WAF propose des groupes de règles préconfigurés gérés par AWS ou des vendeurs du AWS Marketplace, offrant une protection contre les menaces courantes comme l'injection SQL et le cross-site scripting (XSS). Ces règles sont régulièrement mises à jour pour faire face aux vulnérabilités émergentes. - Contrôle des bots : Le service inclut des capacités pour surveiller, bloquer ou limiter le taux des bots courants et omniprésents, aidant à prévenir les attaques automatisées telles que le scraping web et le bourrage d'identifiants. - Surveillance et journalisation en temps réel : AWS WAF s'intègre à Amazon CloudWatch, offrant des métriques en temps réel et capturant des informations détaillées sur les requêtes web. Cette visibilité aide à analyser les modèles de trafic et à affiner les paramètres de sécurité. - Protection contre les DDoS : Lorsqu'il est utilisé conjointement avec AWS Shield, AWS WAF fournit une protection automatique contre les attaques par déni de service distribué (DDoS), garantissant la disponibilité des applications lors de tentatives d'attaques à grande échelle. - Intégration avec les services AWS : AWS WAF s'intègre parfaitement avec d'autres services AWS tels qu'Amazon CloudFront, Application Load Balancer et Amazon API Gateway, permettant une gestion centralisée de la sécurité à travers diverses applications. Valeur principale et problème résolu : AWS WAF répond au besoin critique de sécurité robuste des applications web en fournissant une solution de pare-feu évolutive et personnalisable. Il permet aux organisations de protéger leurs applications web et API contre un large éventail de menaces, y compris les exploits courants et les attaques automatisées, sans compromettre les performances. En offrant des capacités de règles gérées et personnalisées, AWS WAF permet aux entreprises de mettre en œuvre des mesures de sécurité qui s'alignent sur leurs exigences spécifiques. Son intégration avec d'autres services AWS et ses fonctionnalités de surveillance en temps réel renforcent encore la capacité d'une organisation à maintenir une posture de sécurité solide, garantissant la disponibilité et l'intégrité de leurs applications web.

Average Rating: 4.3/5.0

Total Reviews: 65

How Do G2 Users Rate AWS WAF?

  • the product a-t-il été un bon partenaire commercial?: 8.8/10 (Category avg: 8.7/10)
  • Contrôles de la circulation: 8.7/10 (Category avg: 9.1/10)
  • Surveillance de la sécurité: 8.9/10 (Category avg: 9.1/10)
  • Suivi des problèmes: 8.1/10 (Category avg: 8.7/10)

Who Is the Company Behind AWS WAF?

  • Vendeur: Amazon Web Services (AWS)
  • Année de fondation: 2006
  • Emplacement du siège social: Seattle, WA
  • Twitter: @awscloud
    2,232,483 abonnés Twitter
  • Page LinkedIn®: www.linkedin.com
    147,094 employés sur LinkedIn®
  • Propriété: NASDAQ: AMZN

Who Uses This Product?

  • Top Industries: Technologie de l'information et services, Logiciels informatiques
  • Company Size: 36% Large, 35% Medium

What Do G2 Reviewers Say About AWS WAF?

AI-generated summary from verified user reviews

Pros
  • Les utilisateurs apprécient la protection facile contre les attaques courantes fournie par AWS WAF, simplifiant la gestion de la sécurité des sites web.
  • Les utilisateurs apprécient l'intégration native au cloud d'AWS WAF, améliorant la sécurité sans tracas de compatibilité.
  • Les utilisateurs apprécient les règles personnalisées d'AWS WAF, simplifiant la protection contre les attaques web courantes avec un effort manuel minimal.
  • Les utilisateurs apprécient la protection facile contre les attaques courantes fournie par AWS WAF, nécessitant une configuration manuelle minimale.
  • Les utilisateurs apprécient la protection DDoS automatisée d'AWS WAF, qui offre une atténuation rapide et efficace des attaques de couche 7.
Cons
  • Les utilisateurs trouvent la configuration complexe difficile au début, ce qui entraîne de la confusion, notamment en ce qui concerne les prix.
  • Les utilisateurs trouvent la tarification déroutante pour les débutants, ce qui rend l'expérience difficile pour commencer avec AWS WAF.
  • Les utilisateurs trouvent que le blocage inefficace de certaines régions limite leur capacité à appliquer des contrôles d'accès géographiques stricts.

What Are Recent G2 Reviews of AWS WAF?

What Are G2 Users Discussing About AWS WAF?

Azure Application Gateway

La passerelle d'application Azure est un équilibrage de charge de trafic web qui vous permet de gérer le trafic vers vos applications web. Contrairement aux équilibrages de charge traditionnels qui fonctionnent au niveau de la couche de transport (couche 4), la passerelle d'application fonctionne au niveau de la couche application (couche 7), ce qui lui permet de prendre des décisions de routage basées sur des attributs tels que les chemins d'URL et les en-têtes d'hôte. Cette capacité offre un meilleur contrôle sur la manière dont le trafic est distribué vers vos applications, améliorant à la fois la performance et la sécurité. Caractéristiques clés et fonctionnalités : - Équilibrage de charge de couche 7 : Route le trafic en fonction des attributs des requêtes HTTP, permettant un contrôle plus précis de la distribution du trafic. - Pare-feu d'application web (WAF) : Protège les applications contre les vulnérabilités web courantes comme l'injection SQL et le cross-site scripting en surveillant et filtrant les requêtes HTTP. - Terminaison SSL/TLS : Décharge le traitement SSL/TLS vers la passerelle, réduisant la surcharge de chiffrement et de déchiffrement sur les serveurs backend. - Mise à l'échelle automatique : Ajuste automatiquement le nombre d'instances de la passerelle en fonction de la charge de trafic, garantissant une performance optimale et une efficacité des coûts. - Redondance de zone : Distribue les instances à travers plusieurs zones de disponibilité, améliorant la résilience et la disponibilité. - Routage basé sur le chemin d'URL : Dirige les requêtes vers des pools backend en fonction des chemins d'URL, permettant une utilisation efficace des ressources. - Routage basé sur l'en-tête d'hôte : Route le trafic vers différents pools backend en fonction de l'en-tête d'hôte, facilitant l'hébergement multi-sites. - Intégration avec les services Azure : S'intègre parfaitement avec Azure Traffic Manager pour l'équilibrage de charge global et Azure Monitor pour la surveillance et l'alerte centralisées. Valeur principale et solutions pour les utilisateurs : La passerelle d'application Azure offre une solution évolutive et hautement disponible pour gérer le trafic des applications web. En fonctionnant au niveau de la couche application, elle offre des capacités de routage intelligentes qui améliorent la performance et la fiabilité des applications. Le pare-feu d'application web intégré assure une sécurité robuste contre les menaces web courantes, tandis que des fonctionnalités comme la terminaison SSL/TLS et la mise à l'échelle automatique optimisent l'utilisation des ressources et réduisent la surcharge opérationnelle. Cet ensemble complet de fonctionnalités répond aux besoins des organisations cherchant à construire des interfaces web sécurisées, évolutives et efficaces dans Azure.

Average Rating: 4.4/5.0

Total Reviews: 140

How Do G2 Users Rate Azure Application Gateway?

  • the product a-t-il été un bon partenaire commercial?: 8.8/10 (Category avg: 8.7/10)
  • Contrôles de la circulation: 9.4/10 (Category avg: 9.1/10)
  • Surveillance de la sécurité: 9.5/10 (Category avg: 9.1/10)
  • Suivi des problèmes: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind Azure Application Gateway?

  • Vendeur: Microsoft
  • Année de fondation: 1975
  • Emplacement du siège social: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 abonnés Twitter
  • Page LinkedIn®: www.linkedin.com
    231,632 employés sur LinkedIn®
  • Propriété: MSFT

Who Uses This Product?

  • Who Uses This: Ingénieur DevOps, Ingénieur logiciel
  • Top Industries: Technologie de l'information et services, Logiciels informatiques
  • Company Size: 47% Large, 33% Medium

What Do G2 Reviewers Say About Azure Application Gateway?

AI-generated summary from verified user reviews

Pros
  • Les utilisateurs trouvent que la passerelle d'application Azure a une interface conviviale, rendant l'installation et l'intégration fluides et simples.
  • Les utilisateurs soulignent la scalabilité parfaite de l'Azure Application Gateway, améliorant leur expérience de migration vers le cloud et leur efficacité opérationnelle.
  • Les utilisateurs soulignent l'efficacité économique de l'Azure Application Gateway, en faisant un choix judicieux pour la migration vers le cloud.
  • Les utilisateurs apprécient la haute disponibilité et les fonctionnalités étendues de l'Azure Application Gateway, améliorant la stabilité et l'efficacité.
  • Les utilisateurs apprécient les intégrations transparentes de la passerelle d'application Azure, améliorant la connectivité avec d'autres applications Microsoft sans effort.
Cons
  • Les utilisateurs ont souvent du mal avec la complexité d'Azure, ce qui rend difficile le choix des bons outils et services.
  • Les utilisateurs trouvent les coûts élevés de l'Azure Application Gateway préoccupants par rapport à d'autres solutions cloud.
  • Les utilisateurs trouvent la difficulté d'apprentissage de l'Azure Application Gateway difficile, nécessitant une expertise technique pour naviguer dans ses complexités.
  • Les utilisateurs trouvent que la passerelle d'application Azure n'est pas conviviale, citant une interface complexe et des difficultés à naviguer dans les paramètres.
  • Les utilisateurs trouvent les problèmes de complexité de l'Azure Application Gateway accablants, en particulier pour les nouveaux venus qui naviguent dans ses capacités.

What Are Recent G2 Reviews of Azure Application Gateway?

What Are G2 Users Discussing About Azure Application Gateway?

Fortinet Managed Rules for AWS WAF

Les règles WAF de Fortinet sont des signatures de sécurité supplémentaires qui peuvent être utilisées pour renforcer les protections incluses dans le produit de base AWS WAF. Elles sont mises à jour régulièrement pour inclure les dernières informations sur les menaces provenant des laboratoires primés FortiGuard. Le jeu de règles complet OWASP Top 10 offre un package complet pour la protection des applications web proposé par Fortinet pour aider à traiter les 10 principales menaces pour les applications web selon OWASP. Il inclut une protection contre diverses attaques par injection telles que l'injection SQL et de commandes, le cross-site scripting, les exploits généraux et connus, les bots malveillants et les vulnérabilités et expositions communes (CVE).

Average Rating: 4.2/5.0

Total Reviews: 15

How Do G2 Users Rate Fortinet Managed Rules for AWS WAF?

  • the product a-t-il été un bon partenaire commercial?: 9.6/10 (Category avg: 8.7/10)
  • Contrôles de la circulation: 10.0/10 (Category avg: 9.1/10)
  • Surveillance de la sécurité: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Fortinet Managed Rules for AWS WAF?

  • Vendeur: Fortinet
  • Site Web de l'entreprise:
  • Année de fondation: 2000
  • Emplacement du siège social: Sunnyvale, CA
  • Twitter: @Fortinet
    151,422 abonnés Twitter
  • Page LinkedIn®: www.linkedin.com
    16,279 employés sur LinkedIn®

Who Uses This Product?

  • Company Size: 53% Small, 33% Medium

What Do G2 Reviewers Say About Fortinet Managed Rules for AWS WAF?

AI-generated summary from verified user reviews

Pros
  • Les utilisateurs louent la sécurité complète des règles gérées par Fortinet, assurant une protection robuste pour les déploiements AWS API Gateway.
  • Les utilisateurs trouvent les règles gérées de Fortinet pour AWS WAF incroyablement faciles à mettre en œuvre, rationalisant le développement de projets et améliorant la sécurité sans effort.
  • Les utilisateurs soulignent la protection complète offerte par les règles gérées de Fortinet, assurant une sécurité robuste contre diverses menaces sans effort.
  • Les utilisateurs apprécient les intégrations faciles des règles gérées de Fortinet pour AWS WAF, simplifiant la gestion de la sécurité de leur API Gateway.
  • Les utilisateurs trouvent la facilité de mise en œuvre des règles gérées par Fortinet impressionnante, simplifiant la configuration du WAF même pour les débutants.
Cons
  • Les utilisateurs expriment des préoccupations concernant les coûts élevés des règles gérées par Fortinet, impactant particulièrement les petites organisations et les startups.
  • Les utilisateurs trouvent la configuration difficile des règles gérées de Fortinet difficile, surtout ceux qui sont nouveaux dans la gestion AWS WAF.
  • Les utilisateurs sont préoccupés par les coûts élevés associés aux règles gérées de Fortinet pour AWS WAF, ce qui impacte les considérations budgétaires.
  • Les utilisateurs rencontrent une courbe d'apprentissage abrupte avec les règles gérées de Fortinet, rendant la configuration initiale difficile pour les débutants.

What Are Recent G2 Reviews of Fortinet Managed Rules for AWS WAF?

TR7 ASP

An application security platform (ASP) designed by IT users angry and frustrated with the time-to-manage complex legacy application delivery and WAF products. TR7's friendly design, dynamic flow-panel, and rich reporting makes it very easy for IT Teams to increase application performance, improve resilience, and prevent cyber attacks faster. The core components of the platform are: ⚖️ Load Balancer 🚪 Access Policy Manager 🌐 Global Traffic Manager 🛡️ WebApp Firewall (WAF) Effective user access controls make it simple to provide the right access and visibility to the right people, enabling IT Network, Application, and Security teams to work more effectively together, and on their respective priorities. Deploy as physical or virtual appliance, or both, depending on your scope and requirements. Friendly cluster options and attractive economies of scale are designed for you to architect resilience and best practice affordably.

Average Rating: 4.9/5.0

Total Reviews: 25

How Do G2 Users Rate TR7 ASP?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.7/10)
  • Traffic Controls: 9.7/10 (Category avg: 9.1/10)
  • Security Monitoring: 9.5/10 (Category avg: 9.1/10)
  • Issue Tracking: 9.5/10 (Category avg: 8.7/10)

Who Is the Company Behind TR7 ASP?

  • Seller: TR7
  • Year Founded: 2020
  • HQ Location: Ankara, TR
  • LinkedIn® Page: www.linkedin.com
    41 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 58% Large, 35% Medium

What Do G2 Reviewers Say About TR7 ASP?

AI-generated summary from verified user reviews

Pros
  • Users value the excellent technical support from TR7 ASP, enhancing their experience with timely assistance and solutions.
  • Users value the efficient load balancing of TR7 ASP, citing reliability and seamless traffic distribution even under heavy loads.
  • Users highlight the user-friendly interface of TR7 ASP, making operations simple and efficient with excellent support.
  • Users praise the exceptional reliability of TR7 ASP, effectively resolving traffic routing and security issues.
  • Users appreciate the exceptionally user-friendly configuration of TR7 ASP, making management quick and straightforward.
Cons
  • Users find the complex operations of TR7 ASP make software updates more challenging compared to similar products.
  • Users find the complex setup of TR7 ASP inconvenient compared to other similar products, complicating usability.
  • Users find the difficult setup due to the absence of an in-place upgrade for updates.
  • Users find the limited customization of TR7 ASP screens restrictive, wishing for options to better meet their needs.
  • Users desire more features, particularly API security, to enhance the overall functionality of TR7 ASP.

What Are Recent G2 Reviews of TR7 ASP?

Azure Web Application Firewall

Azure Web Application Firewall is a cloud-native security service designed to protect web applications and APIs from common web vulnerabilities and attacks, such as SQL injection and cross-site scripting. By integrating seamlessly with Azure services like Application Gateway, Front Door, and Content Delivery Network , Azure WAF offers centralized protection, ensuring the security and availability of web applications without the need for modifications to backend code. Key Features and Functionality: - Managed Rule Sets: Azure WAF provides pre-configured rule sets that are regularly updated to defend against the latest threats, including the OWASP Top 10 security risks. - Customizable Rules and Policies: Users can create custom rules tailored to specific application requirements, allowing for granular control over security measures. - Real-Time Monitoring and Logging: Integrated with Azure Monitor, Azure WAF offers detailed logging and real-time monitoring of security events, enabling prompt detection and response to potential threats. - Flexible Deployment Options: Azure WAF can be deployed with Azure Application Gateway, Azure Front Door, and Azure CDN, providing versatile options to suit various architectural needs. - Bot Protection and DDoS Mitigation: The service includes features to detect and block malicious bot traffic and offers protection against Distributed Denial of Service attacks at the network edge. Primary Value and Problem Solved: Azure Web Application Firewall addresses the critical need for robust web application security by providing centralized protection against a wide range of web-based attacks. By leveraging managed and custom rule sets, real-time monitoring, and seamless integration with other Azure services, Azure WAF simplifies security management, reduces the risk of data breaches, and ensures the continuous availability of web applications. This comprehensive approach allows organizations to focus on delivering their services without compromising on security.

Average Rating: 4.4/5.0

Total Reviews: 31

How Do G2 Users Rate Azure Web Application Firewall?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 8.7/10)
  • Traffic Controls: 8.1/10 (Category avg: 9.1/10)
  • Security Monitoring: 8.5/10 (Category avg: 9.1/10)
  • Issue Tracking: 8.1/10 (Category avg: 8.7/10)

Who Is the Company Behind Azure Web Application Firewall?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    231,632 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 42% Medium, 42% Large

What Are Recent G2 Reviews of Azure Web Application Firewall?

What Are G2 Users Discussing About Azure Web Application Firewall?

Google Cloud Armor

Google Cloud Armor est une solution de sécurité complète conçue pour protéger les applications et les sites web contre une variété de menaces, y compris les attaques par déni de service distribué (DDoS) et les vulnérabilités web courantes. En tirant parti de l'infrastructure mondiale de Google, Cloud Armor offre des défenses robustes pour garantir la disponibilité et la sécurité des services en ligne. Caractéristiques clés et fonctionnalités : - Défense DDoS intégrée : Fournit une protection automatique contre les attaques DDoS de couche 3 et 4, bénéficiant de l'expérience étendue de Google dans la protection des grandes propriétés internet. - Protection adaptative : Utilise l'apprentissage automatique pour détecter et atténuer les attaques DDoS de couche 7 à haut volume, en analysant les modèles de trafic en temps réel pour identifier et répondre aux menaces. - Règles WAF préconfigurées : Offre des règles de pare-feu d'application web prêtes à l'emploi basées sur les normes de l'industrie pour se défendre contre les vulnérabilités courantes, telles que les attaques par script intersite (XSS) et les injections SQL (SQLi). - Gestion des bots : S'intègre avec reCAPTCHA Enterprise pour fournir une protection automatisée contre les bots malveillants, aidant à prévenir la fraude et les abus à la périphérie du réseau. - Limitation de débit : Met en œuvre des règles basées sur le débit pour contrôler le volume des requêtes entrantes, protégeant les applications contre une surcharge de trafic excessive et garantissant l'accès aux utilisateurs légitimes. Valeur principale et solutions pour les utilisateurs : Google Cloud Armor offre une protection de niveau entreprise en combinant des capacités de défense DDoS et de pare-feu d'application web à un prix mensuel prévisible. Il répond aux défis de sécurité critiques en atténuant les risques du Top 10 de l'OWASP et en fournissant des défenses adaptatives basées sur l'apprentissage automatique contre les attaques sophistiquées. En s'intégrant parfaitement à l'infrastructure mondiale d'équilibrage de charge de Google, Cloud Armor garantit que les applications restent sécurisées et disponibles, quel que soit l'environnement de déploiement, qu'il soit sur site, dans le cloud ou dans une configuration hybride.

Average Rating: 4.0/5.0

Total Reviews: 23

How Do G2 Users Rate Google Cloud Armor?

  • the product a-t-il été un bon partenaire commercial?: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind Google Cloud Armor?

  • Vendeur: Google
  • Année de fondation: 1998
  • Emplacement du siège social: Mountain View, CA
  • Twitter: @google
    31,899,995 abonnés Twitter
  • Page LinkedIn®: www.linkedin.com
    341,888 employés sur LinkedIn®
  • Propriété: NASDAQ:GOOG

Who Uses This Product?

  • Top Industries: Sécurité informatique et réseau
  • Company Size: 52% Small, 39% Large

What Do G2 Reviewers Say About Google Cloud Armor?

AI-generated summary from verified user reviews

Pros
  • Les utilisateurs apprécient la tarification flexible de Google Cloud Armor, bénéficiant de remises soutenues pour une meilleure efficacité des coûts.
  • Les utilisateurs apprécient la scalabilité de Google Cloud Armor, permettant un ajustement facile des ressources selon les besoins.
  • Les utilisateurs apprécient les fonctionnalités de sécurité avancées de Google Cloud Armor qui garantissent une protection robuste et la conformité.
Cons
  • Les utilisateurs trouvent la tarification complexe de Google Cloud Armor difficile, ce qui impacte leur expérience globale et leur prise de décision.
  • Les utilisateurs trouvent des problèmes de coût avec Google Cloud Armor en raison de la tarification complexe et des plans de support coûteux.
  • Les utilisateurs sont confrontés à une disponibilité limitée de Google Cloud Armor par rapport aux concurrents, ce qui affecte l'accessibilité pour certaines régions.
  • Les utilisateurs trouvent des fonctionnalités limitées dans les outils d'entreprise de Google Cloud Armor, ce qui affecte l'utilité et la satisfaction globales.
  • Les utilisateurs trouvent que la consommation de temps pour apprendre GCP est un obstacle significatif dans leur expérience.

What Are Recent G2 Reviews of Google Cloud Armor?

What Are G2 Users Discussing About Google Cloud Armor?

Barracuda Web Application Firewall

Barracuda Web Application Firewall (WAF) is purpose-built to protect your web, mobile, and API applications from today’s most advanced threats. It helps prevent data breaches and ensures business continuity by blocking OWASP Top 10 attacks, L4–L7 DDoS, zero-day exploits, and more. With Advanced Bot Protection powered by cloud-based machine learning, Barracuda WAF detects and stops malicious bots responsible for web scraping, credential stuffing, and account takeover attempts—before they can do damage. Flexible deployment options include hardware appliances, virtual machines, public cloud platforms, and containers—so you can secure your applications wherever they live.

Average Rating: 4.3/5.0

Total Reviews: 13

How Do G2 Users Rate Barracuda Web Application Firewall?

  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 8.7/10)
  • Traffic Controls: 8.3/10 (Category avg: 9.1/10)
  • Security Monitoring: 8.8/10 (Category avg: 9.1/10)
  • Issue Tracking: 5.8/10 (Category avg: 8.7/10)

Who Is the Company Behind Barracuda Web Application Firewall?

  • Seller: Barracuda
  • Year Founded: 2002
  • HQ Location: Campbell, CA
  • Twitter: @Barracuda
    15,239 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,248 employees on LinkedIn®
  • Ownership: Private

Who Uses This Product?

  • Company Size: 64% Medium, 21% Large

What Do G2 Reviewers Say About Barracuda Web Application Firewall?

AI-generated summary from verified user reviews

Pros
  • Users value the easy configuration of Barracuda Web Application Firewall, simplifying the setup and management process.
  • Users appreciate the strong layered protection offered by Barracuda Web Application Firewall for safeguarding sensitive data.
  • Users value the layered protection Barracuda provides for Web Apps and APIs, ensuring data security and compliance.
  • Users value the management efficiency of Barracuda Web Application Firewall, praising its easy configuration and setup.
  • Users find the setup very easy with Barracuda Web Application Firewall, appreciating its simplicity in configuration and management.
Cons
  • Users face false positives with Barracuda WAF, necessitating manual reviews and causing frustration in threat detection.
  • Users often face poor customer support, finding technical issues take too long to resolve and troubleshoot effectively.

What Are Recent G2 Reviews of Barracuda Web Application Firewall?

What Are G2 Users Discussing About Barracuda Web Application Firewall?

F5 NGINX

NGINX, Inc. is the company behind NGINX, the popular open source project trusted by more than 400 million sites. We offer a suite of technologies for developing and delivering modern applications. The NGINX Application Platform enables enterprises undergoing digital transformation to modernize legacy, monolithic applications as well as deliver new, microservices‑based applications. Companies like Netflix, Starbucks, and McDonalds rely on NGINX to reduce costs, improve resiliency, and speed innovation. NGINX investors include Blue Cloud Ventures, e.ventures, Goldman Sachs, Index Ventures, MSD Capital, NEA, Runa Capital, and Telstra Ventures. NGINX, Inc. is headquartered in San Francisco, CA, with an EMEA head office in Cork, Ireland and APAC head office in Singapore. Learn more at https://www.nginx.com/

Average Rating: 4.6/5.0

Total Reviews: 112

How Do G2 Users Rate F5 NGINX?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 8.7/10)
  • Traffic Controls: 9.0/10 (Category avg: 9.1/10)
  • Security Monitoring: 9.1/10 (Category avg: 9.1/10)
  • Issue Tracking: 8.9/10 (Category avg: 8.7/10)

Who Is the Company Behind F5 NGINX?

  • Seller: F5
  • HQ Location: Seattle, Washington
  • Twitter: @F5Networks
    1,385 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,165 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 41% Small, 40% Medium

What Do G2 Reviewers Say About F5 NGINX?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of configuration across platforms with F5 NGINX, enhancing their installation experience.

What Are Recent G2 Reviews of F5 NGINX?

What Are G2 Users Discussing About F5 NGINX?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated January 22, 2025

Learn More About Web Application Firewalls (WAF)


What is Web Application Firewall (WAF) Software?

WAF software products are used to protect web applications and websites from threats or attacks. The firewall monitors traffic between users, applications, and other internet sources. They're effective in defending against cross-site forgery, cross-site scripting (XSS attacks), SQL injection, DDoS attacks, and many other kinds of attacks.

These software solutions provide automatic defense and allow administrative control over rule sets and customization since some applications may have unique traffic trends, zero-day threats, or web application vulnerabilities. These tools also provide logging features to document and analyze attacks, incidents, and normal application behaviors.

Companies with web applications should use WAF tools to ensure all weak spots in the application itself are filled. Without WAF, many threats may go undetected, and data leakage may occur. They have truly become an obligatory component of any business-critical web application containing sensitive information.

Key Benefits of Web Application Firewall (WAF) Software

  • Protection against web-based threats
  • Historical documentation of incidents and events
  • Elastic, scalable web application protection


Why Use Web Application Firewall (WAF) Software?

There are a variety of benefits associated with WAF tools and ways they can boost security of applications deployed online. Most of the reasoning behind WAF usage is the generally accepted belief that web-based threats should be a concern for all businesses. Therefore, all businesses deploying web-based applications should be sure they are doing all they can to defend against the myriad cyberthreats that exist today.

Some of the numerous threats WAF products can help defend against include:

  • Cross-Site Scripting (XSS) — Cross-site scripting (XSS) is an attack where a malicious script is injected into websites using a web application to send malicious code. Malicious scripts can be used to access information such as cookies, session tokens, and other sensitive data collected by web browsers.
  • Injection Flaws — Injection flaws are vulnerabilities which allow attackers to send code through an application to another system. The most common type is a SQL injection. In this scenario, an attacker finds a point in which the web application passes through a database, executes their code, and can begin querying whatever information they want.
  • Malicious File Execution — Malicious file execution is accomplished when an attacker is able to input malicious files that are uploaded to the web server or application server. These files can be executed upon upload and completely compromise an application server.
  • Insecure Direct Object Reference — Insecure direct object reference occurs when user input can directly access an application's internal components. These vulnerabilities can allow attackers to bypass security protocols and access resources, files, and data directly.
  • Cross-Site Request Forgery (CSRF) — CSRF attacks force users to execute actions on a web application the user has permission to access. These actions can force users to unwillingly submit requests that may damage the web application or change their credentials to something the attacker can reuse to gain access to an application at a future date.
  • Information Leakage — Information leakage can occur when unauthorized parties are able to access databases or visit URLs that are not linked from the site. Attackers may be capable of accessing sensitive files such as password backups or unpublished documents.
  • Improper Error Handling — Error handling refers to preprogrammed measures that allow applications to dismiss unexpected events without exposing sensitive information. Improper error handling leads to a number of various issues, including the release of data, vulnerability exposure, and application failure.
  • Broken Authentication — Broken authentication is the result of improper credential management functions. If authentication measures fail to function, attackers can walk by security measures without the valid identification. This can lead to attackers gaining direct access to entire networks, servers, and applications.
  • Session Management — Session management errors occur when attackers manipulate or capture the tokenized ID provided to authenticated visitors. Attackers can impersonate generic users or target privileged users to gain access control and hijack an application.
  • Insecure Cryptographic Storage — Cryptographic storage is used to authenticate and protect communications online. Attackers may identify and obtain unencrypted or poorly encrypted resources that may contain sensitive information. Proper encryption typically protects against this, but poor key storage, weak algorithms, and flawed key generation may put sensitive data at risk.
  • Insecure Communications — Insecure communications occur when messages exchanged between clients and servers becomes visible. Poor network firewalls and network security policies can lead to easy access for attackers by gaining access to a local network or carrier device or installing malware on a device. Once applications are exploited, individual user information and other sensitive data becomes extremely vulnerable.
  • Failure to Restrict URL Access — Applications may fail to restrict URL access to unauthorized parties who attempt to visit unlinked URLs or files without permission. Attackers may bypass security by directly accessing URLs containing sensitive information or data files. URL restriction can be accomplished by utilizing page tokens or encrypting URLs to restrict access unless they visit restricted pages through approved navigational paths.


Who Uses Web Application Firewall (WAF) Software?

The actual individuals using application firewalls are software developers and security professionals. The developer will typically build and implement the firewall, while it is maintained and monitored by security operations teams. Still, there are a few industries that may be more inclined to use WAF tools for various purposes.

Internet Businesses — Internet businesses are a natural fit for WAF tools. They often have one or multiple public-facing web applications and various internal web apps for employee use. Both of these kinds of applications should be guarded by some kind of firewall, as well as additional layers of security. While nearly all modern businesses use web applications in some capacity, internet-centric businesses are more susceptible to attacks simply because they likely possess more web apps.

E-Commerce Professionals — E-commerce professionals and e-commerce businesses that build their own online tools should be using WAF technology. Many e-commerce applications are managed by some kind of SaaS provider, but custom-built tools are incredibly vulnerable without an application firewall. E-commerce businesses who fail to protect their applications put the data of their visitors, customers, and business on the line.

Compliant-Required Industries — Industries that require a higher level of compliance for data security should use a web application firewall for any application that communicates with a server or network with access to sensitive information. The most common business types with increased compliance requirements include health care, insurance, and energy industries. But many countries and localities have expanded IT compliance requirements across industries to prevent data breaches and the release of sensitive information.


Web Application Firewall (WAF) Software Features

Some WAF products may be geared toward specific applications, but most share a similar set of core security features and capabilities. The following are a handful of common features to look for when considering the adoption of WAF tools.

Logging and Reporting — Provides required reports to manage the business. Provides adequate logging to troubleshoot and support auditing.

Issue Tracking — Tracks security issues as they arise and manages various aspects of the mitigation process.

Security Monitoring — Detects anomalies in functionality, user accessibility, traffic flows, and tampering.

Reporting and Analytics — Provides documentation and analytical capabilities for data gathered by the WAF product.

Application-Layer Control — Gives user-configurable WAF rules, such as application control requests, management protocols, and authentication policies, to increase security.

Traffic Control — Limits access to suspicious visitors and monitors for traffic spikes to prevent overloads like DDoS attacks.

Network Control — Lets users provision networks, deliver content, balance loads, and manage traffic.