Likelihood to Recommend Most suited if you have a very strong presence in AWS. It is natively available as an add on service. You can also track the costs overtime based on usage. There is still a lot of improvement on the features and the user interface that can be implemented over time
Read full review So a lot of companies that have a digital side and they have a lot of applications in the cloud, this is one of those areas that it can protect the net so it can lock 'em down, it'll build a baseline so you understand what that application's doing. So if it sees something not normal, it'll get protected against that.
Read full review Pros Protect any application against the most common attacks. Provides better visibility of web traffic. It allows us to control the traffic in different ways in which it is enabled or blocked through the implementation of security rules developed personally according to our needs. It is able to block common attacks such as SQL code injection. It allows defining specific rules for applications, thus increasing web security as they are developed. Read full review Layer seven attacks are becoming far more common. Traditionally it was always layered three, layer four, where you get an additional firewall, but with the application layer attacks become more frequent, more popular, et cetera. So having the web application firewall protecting us, and then with the recent Log4j, that's the most recent use case when it gave us that instant level of protection whilst we remediated the Log4j that we had that and the F5 Distributed Cloud WAF was protecting us. I have a great relationship with the account manager, my account manager, and I think he drives the best price possible, um, for me, and I'm happy with that price. F5 Distributed Cloud WAF is always innovating and evolving. We run a very competitive proof value where we run numerous competitors against each other, and then we evaluate from that and then make the selection, and F5 Distributed Cloud WAF was the winner. Read full review Cons AWS WAF is a bit costly if used for single applications. they should provide attack-wise protection, like if my certain type of application is vulnerable to DDOS then I should be able to buy WAF, especially for that attack. CLI tool to test in offline mode if possible. Read full review So we just had some performance issues when it comes to routing. Because the web application firewall sits in front of our website, which is hosted on-site, we had some trouble with the VGP protocols between the two sites and it took us a while to figure it out. So that is probably one area where we could improve. Otherwise, when it comes to the WAF functionality itself, it's really good. Read full review Usability The product is highly scalable. It is easy to configure the rules and thereby helps us to mitigate many vulnerabilities. The interface and programming of the firewall provisions were easy to setup. Amazon clearly spent a lot of time figuring this out and perfecting it. It allows users to do customized configurations based on their needs. It provides protection against a number of security issues like XSS, SQL injection, etc. I would definitely recommend this for protecting your infra as you scale, since this basically protects and filters all requests hitting your application server.
Read full review I believe is a solution that was designed from the start to be simple and easy to use. Coming from Imperva, it simply eased the burden and complexity of managing and securing our apps on different environments (cloud and on-prem). It easy to scale and very quick to deploy (as a cloud waf should be), provide us with DevOps integrations, visibility and automatic insights from multiple events that guarantee peace of mind for us analysts and opp managers.
Read full review Support Rating If you're intending to use AWS WAF, I would say that you absolutely should sign up for support. AWS Support is excellent and they can help you in a really good way to solve your issues.
Read full review Alternatives Considered Unlike these other AWS tools, WAF provides real-time traffic control, rules that can be customized according to the needs of the user, and is based on an implementation in the cloud which avoids the use of memory on computers as well as an account with a very affordable cost for any user or company
Read full review The other one that I've used in the past, they're very similar and I haven't used it recently, so I can't do a side-by-side comparison today. But I can say that F5 does everything we want it to do consistent with what this other product did do and it's got enhanced features and of course we have a long history with F5 as a product set in general.
Read full review Return on Investment The overall security of the web application increased effectively after deploying AWS WAF No negative impacts were seen in the business The developers were more confident in the overall security model of the web application being developed and it was easy to integrate WAF into the existing system as the application was also using AWS platform Read full review Accelerated time to value as it was a requirement for a workload being provisioned on that cloud As an existing f5 customer, access to their solutions integrator (GridZero) made the sizing, licensing, purchases, and downloading of the software very quick and painless Read full review ScreenShots