Likelihood to Recommend Most suited if you have a very strong presence in AWS. It is natively available as an add on service. You can also track the costs overtime based on usage. There is still a lot of improvement on the features and the user interface that can be implemented over time
Read full review [NGINX] is very well suited for high performance. I have seen it used on servers with 1k current connections with no issues. Despite seeing it used in many environments I've never seen software developers use it over apache, express, IIS in local dev environments so it may be more difficult to setup. I've also seen it used to load balance again without issues.
Read full review Pros Protect any application against the most common attacks. Provides better visibility of web traffic. It allows us to control the traffic in different ways in which it is enabled or blocked through the implementation of security rules developed personally according to our needs. It is able to block common attacks such as SQL code injection. It allows defining specific rules for applications, thus increasing web security as they are developed. Read full review Very low memory usage. Can handle many more connections than alternatives (like Apache HTTPD) due to low overhead. (event-based architecture). Great at serving static content. Scales very well. Easy to host multiple Nginx servers to promote high availability. Open-Source (no cost)! Read full review Cons AWS WAF is a bit costly if used for single applications. they should provide attack-wise protection, like if my certain type of application is vulnerable to DDOS then I should be able to buy WAF, especially for that attack. CLI tool to test in offline mode if possible. Read full review Customer support can be strangely condescending, perhaps it's a language issue? I find it a little weird how the release versions used for Nginx+ aren't the same as for open source version. It can be very confusing to determine the cross-compatibility of modules, etc., because of this. It seems like some (most?) modules on their own site are ancient and no longer supported, so their documentation in this area needs work. It's difficult to navigate between nginx.com commercial site and customer support. They need to be integrated together. I'd love to see more work done on nginx+ monitoring without requiring logging every request. I understand that many statistics can only be derived from logs, but plenty should work without that. Logging is not an option in many environments. Read full review Likelihood to Renew Great value for the product
Read full review Usability The product is highly scalable. It is easy to configure the rules and thereby helps us to mitigate many vulnerabilities. The interface and programming of the firewall provisions were easy to setup. Amazon clearly spent a lot of time figuring this out and perfecting it. It allows users to do customized configurations based on their needs. It provides protection against a number of security issues like XSS, SQL injection, etc. I would definitely recommend this for protecting your infra as you scale, since this basically protects and filters all requests hitting your application server.
Read full review Front end proxy and reverse proxy of Nginx is always useful. I always prefer to Nginx in overall usability when you have application server and database or multiple application servers and single database i.e. clustered application . Nginx provides really good features and flexibility which helps the system administrator in case of troubleshooting and also from the administration perspective . Also, Nginx doesn't delay any request because of internal performance issues.
Read full review Support Rating If you're intending to use AWS WAF, I would say that you absolutely should sign up for support. AWS Support is excellent and they can help you in a really good way to solve your issues.
Read full review John Reeve Principal, Lead developer, Lead designer
Read full review Alternatives Considered Unlike these other AWS tools, WAF provides real-time traffic control, rules that can be customized according to the needs of the user, and is based on an implementation in the cloud which avoids the use of memory on computers as well as an account with a very affordable cost for any user or company
Read full review We have used Traffic, Apache, Google Cloud Load Balancing and other managed cloud-based load balancers. When it comes to scale and customization nothing beats Nginx. We selected Nginx over the others because
we have a large number of services and we can manage a single Nginx instance for all of them we have high impact services and Nginx never breaks a sweat under load individual services have special considerations and Nginx lets us configure each one uniquely Read full review Return on Investment The overall security of the web application increased effectively after deploying AWS WAF No negative impacts were seen in the business The developers were more confident in the overall security model of the web application being developed and it was easy to integrate WAF into the existing system as the application was also using AWS platform Read full review Nginx has decreased the burden of web server administration and maintenance, and we are spending less time on server issues than when we were using Apache. Nginx has allowed more people in our company to get involved with configuring things on the web server, so there's no longer a single point of failure ("the Apache guy"). Nginx has given us the ability to handle a larger number of requests without scaling up in hardware quite so quickly. Read full review ScreenShots