Likelihood to Recommend Most suited if you have a very strong presence in AWS. It is natively available as an add on service. You can also track the costs overtime based on usage. There is still a lot of improvement on the features and the user interface that can be implemented over time
Read full review These devices caused more problems for our company than benefits, I would never recommend these to colleagues.
Read full review Pros Protect any application against the most common attacks. Provides better visibility of web traffic. It allows us to control the traffic in different ways in which it is enabled or blocked through the implementation of security rules developed personally according to our needs. It is able to block common attacks such as SQL code injection. It allows defining specific rules for applications, thus increasing web security as they are developed. Read full review Cons AWS WAF is a bit costly if used for single applications. they should provide attack-wise protection, like if my certain type of application is vulnerable to DDOS then I should be able to buy WAF, especially for that attack. CLI tool to test in offline mode if possible. Read full review The software web application is beyond terrible, in most of the cases the web was broken or did not have similar functionality the command line interface had. The command line interface wasn't a natural looking interface, it was very fumbled and while it ran on Linux, the interface was all menus and sub-menus. When enabling different pools for different web services, when a new pool was activated, the old pool connections were all reset instead of allowing HTTP sessions to naturally expire. Read full review Usability The product is highly scalable. It is easy to configure the rules and thereby helps us to mitigate many vulnerabilities. The interface and programming of the firewall provisions were easy to setup. Amazon clearly spent a lot of time figuring this out and perfecting it. It allows users to do customized configurations based on their needs. It provides protection against a number of security issues like XSS, SQL injection, etc. I would definitely recommend this for protecting your infra as you scale, since this basically protects and filters all requests hitting your application server.
Read full review Support Rating If you're intending to use AWS WAF, I would say that you absolutely should sign up for support. AWS Support is excellent and they can help you in a really good way to solve your issues.
Read full review Alternatives Considered Unlike these other AWS tools, WAF provides real-time traffic control, rules that can be customized according to the needs of the user, and is based on an implementation in the cloud which avoids the use of memory on computers as well as an account with a very affordable cost for any user or company
Read full review We moved away from Alteon to F5 BigIP LTM and just by swapping out the hardware, we saw 40% speed increase in our applications. Everything else is much improved as well, from the web interface to the command line to the API.
Read full review Return on Investment The overall security of the web application increased effectively after deploying AWS WAF No negative impacts were seen in the business The developers were more confident in the overall security model of the web application being developed and it was easy to integrate WAF into the existing system as the application was also using AWS platform Read full review While running on these devices, every release caused many interruptions in service and caused thousands of dollars of lost revenue. Read full review ScreenShots