• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. AWS WAF
Logo of AWS WAF

AWS WAF

byAmazon Web Services (AWS)
in
4.4
Market Presence: Cloud Web Application and API Protection, DDoS Mitigation Solutions

Overview

Product Information on AWS WAF

Updated 13th October 2025

What is AWS WAF?

AWS WAF is a web application firewall software designed to help organizations protect their web applications from common internet threats. The software enables users to create security rules that allow, block, or monitor web requests based on specific criteria such as IP addresses, HTTP headers, and body data. AWS WAF provides features for filtering traffic, preventing attacks including SQL injection and cross site scripting, and managing bot traffic. It integrates with other AWS services to enhance security posture, offers real time visibility into web traffic, and automates responses to detected threats. The software addresses the challenge of securing web applications against evolving cyber risks and helps organizations maintain compliance with security standards.

AWS WAF Pricing

AWS WAF software uses a pay-as-you-go pricing model where charges are based on usage components such as the number of web access control lists created, the number of rules added per web ACL, and the volume of web requests processed. There is no upfront cost or required long-term commitment, and users are billed monthly based on actual usage.

Overall experience with AWS WAF

SENIOR CYBERSECURITY ENGINEER
1B - 3B USD, Transportation
FAVORABLE

“AWS WAF Eases Integration But Requires Additional Investment In Managed Rule Sets”

4.0
Sep 20, 2025
For our small subsidiary, which is fully invested in the AWS ecosystem, using the AWS WAF was a natural and logical choice. Our overall experience has been very positive. It provides a robust layer of security for our public-facing applications running behind our Application Load Balancers and CloudFront distributions. The ability to deploy and manage it natively within the AWS console is a huge operational advantage for a small IT team like ours. It effectively blocks the common web exploits we worry about, but it's not a simple "on" switch; it requires a thoughtful approach to rule management.
IT Associate
500M - 1B USD, Banking
CRITICAL

“Limited Features Available Despite Ease of Use for New Tenant Solutions”

3.0
Jul 16, 2025
needed functionality, but limited options compared to other on prem

About Company

Company Description

Updated 6th March 2025

Amazon Web Services (AWS), established in 2006, is focused on providing essential infrastructure services to businesses globally in the form of cloud computing. The key advantage offered through cloud computing, particularly via AWS, is its capacity to shift fixed infrastructure expenses into flexible costs. Businesses have been able to forgo extensive planning and procurement of servers and other Information Technology (IT) resources, owing to AWS. AWS seeks to provide businesses with prompt and cost-effective access to resources using Amazon's expertise and economies of scale, as and when their business requires. Currently, AWS offers a robust, scalable, economic infrastructure platform on the cloud powering an extensive array of businesses worldwide. It operates across numerous industries with data center locations in various parts of the globe including U.S., Europe, Singapore, and Japan.

Company Details

Updated 23rd December 2024
Company type
Public
Year Founded
2006
Head office location
Seattle, United States
Number of employees
10001+
Website
http://aws.amazon.com

Do You Manage Peer Insights at Amazon Web Services (AWS)?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About AWS WAF
Reviewer Insights for: AWS WAF
Deciding Factors: AWS WAF Vs. Market Average
Performance of AWS WAF Across Market Features

AWS WAF Likes & Dislikes

Like

The best feature by far is its seamless integration with other AWS services. There are no extra servers to manage, no complex DNS changes to reroute traffic. You can attach the WAF to an ALB or CloudFront distribution with a few clicks, and it just works. The pay-as-you-go pricing model is also perfect for our budget, as we avoid the massive upfront cost of a traditional WAF appliance. I also really value the AWS Marketplace for WAF rules. Being able to subscribe to managed rule sets from other vendors gives us enterprise-grade protection without needing a dedicated security expert on staff to write and maintain complex rules.

Like

easy to use on new tenant solutions

Like

What I like most about AWS WAF is how smoothly it integrates with the rest of the AWS ecosystem. Managed rules are very effective against common threats, which saves time and effort. Also the flexibility to create custom rules for our applications it gives a strong balance of ease of use and control. Overall, it makes securing applications feel reliable.

Dislike

The primary challenge is that the AWS WAF, by itself, is essentially a blank slate. Without adding managed rules, you are responsible for writing, testing, and maintaining every single rule yourself. This can be incredibly complex and time-consuming, and there's a real risk of writing a bad rule that either blocks legitimate traffic or fails to stop an attack. Consequently, the third-party managed rule sets are practically a requirement, which adds a significant and recurring cost on top of the base AWS WAF pricing. This hidden cost can be a surprise if you haven't budgeted for it.

Dislike

some limitations with their packet inspection tooling

Dislike

The only thing I would mention is about the initial learning of this as setting up the rules can feel complex. Pricing is also on the slightly higher side compared to othe competitors

Top AWS WAF Alternatives

Logo of Imperva Application Security Platform
1. Imperva Application Security Platform
4.7
(542 Ratings)
Logo of Fastly Next-Gen WAF
2. Fastly Next-Gen WAF
4.8
(535 Ratings)
Logo of Cloudflare Application Services
3. Cloudflare Application Services
4.5
(476 Ratings)
View All Alternatives

Peer Discussions

AWS WAF Reviews and Ratings

4.4

(374 Ratings)

Rating Distribution

5 Star
49%
4 Star
46%
3 Star
4%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.4

Integration & Deployment

4.6

Service & Support

4.5

Product Capabilities

4.5

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • SENIOR CYBERSECURITY ENGINEER
    1B-10B USD
    Transportation
    Review Source

    AWS WAF Eases Integration But Requires Additional Investment In Managed Rule Sets

    4.0
    Sep 20, 2025
    For our small subsidiary, which is fully invested in the AWS ecosystem, using the AWS WAF was a natural and logical choice. Our overall experience has been very positive. It provides a robust layer of security for our public-facing applications running behind our Application Load Balancers and CloudFront distributions. The ability to deploy and manage it natively within the AWS console is a huge operational advantage for a small IT team like ours. It effectively blocks the common web exploits we worry about, but it's not a simple "on" switch; it requires a thoughtful approach to rule management.
  • IT SERVICES ASSOCIATE
    50M-1B USD
    IT Services
    Review Source

    Seamless protection with easy integration into the AWS System

    5.0
    Sep 28, 2025
    The overall experience with AWS WAF is really good. The integration with other AWS services is smooth and it provides good customization. It offers a strong protection with the managed rules that cover almost all threats.
  • DC & CLOUD MANAGER
    50M-1B USD
    Consumer Goods
    Review Source

    Cloudfront Integration Simplifies Setup But Advanced Protection Increases Cost

    5.0
    Sep 23, 2025
    The product works well in most cases; there are cases where some extra features or flexibility could be added to be more intuitive. To fully leverage its benefits, it requires more advanced skills or add customized rules. Although they have improved the console, it needs more improvement.
  • SR. SYSTEMS ADMINISTRATOR
    <50M USD
    Media
    Review Source

    AWS WAF Effectively Blocks Threats But Legitimate Traffic Investigations Can Be Complex

    5.0
    Aug 26, 2025
    We have been using AWS WAF to secure our websites and API's. It protects the published services from DDoS, vulnerabilities and other bot attacks. We have found it to be instrumental since we haven't encountered any breaches or downtime associated with the resources that WAF is protecting.
  • Security Analyst
    50M-1B USD
    Software
    Review Source

    AWS WAF is excellent, but requires extra products to complement it, raising costs

    4.0
    Aug 18, 2025
    We use AWS WAF as a complement to other WAFs to prevent incoming traffic at an upper layer together with CloudFront, and it performs excellently overall.
...
Showing Result 1-5 of 488

Recommended Gartner Research

  • Market Guide for Cloud Web Application and API Protection

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.