AWS WAF vs. F5 Distributed Cloud WAF (Web Application Firewall)

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
AWS WAF
Score 7.4 out of 10
N/A
Amazon Web Services offers AWS WAF (web application firewall) to protect web applications from malicious behavior that might impede the applications functioning and performance, with customizable rules to prevent known harmful behaviors and an API for creating and deploying web security rules.
$0.60
per 1 million requests
F5 Distributed Cloud WAF (Web Application Firewall)
Score 9.0 out of 10
N/A
F5 Distributed Cloud WAF leverages F5's Advanced WAF technology, delivering WAF-as-a-Service and combining signature- and behavior-based protection for web applications. It acts as an intermediate proxy to inspect application requests and responses to block and mitigate a broad spectrum of risks stemming from the OW ASP Top 10, persistent and coordinated threat campaigns, bots, and layer 7 DoS.N/A
Pricing
AWS WAFF5 Distributed Cloud WAF (Web Application Firewall)
Editions & Modules
Resource Type - Request
$0.60
per 1 million requests
Resource Type - Rule
$1.00
per month (prorated hourly)
Resource Type - Web ACL
$5.00
per month (prorated hourly)
No answers on this topic
Offerings
Pricing Offerings
AWS WAFF5 Distributed Cloud WAF (Web Application Firewall)
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
AWS WAFF5 Distributed Cloud WAF (Web Application Firewall)
Best Alternatives
AWS WAFF5 Distributed Cloud WAF (Web Application Firewall)
Small Businesses
Cloudflare
Cloudflare
Score 8.7 out of 10
Cloudflare
Cloudflare
Score 8.7 out of 10
Medium-sized Companies
F5 Big-IP Advanced WAF
F5 Big-IP Advanced WAF
Score 9.3 out of 10
F5 Big-IP Advanced WAF
F5 Big-IP Advanced WAF
Score 9.3 out of 10
Enterprises
F5 Big-IP Advanced WAF
F5 Big-IP Advanced WAF
Score 9.3 out of 10
F5 Big-IP Advanced WAF
F5 Big-IP Advanced WAF
Score 9.3 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
AWS WAFF5 Distributed Cloud WAF (Web Application Firewall)
Likelihood to Recommend
9.0
(0 ratings)
8.9
(0 ratings)
Likelihood to Renew
9.0
(0 ratings)
-
(0 ratings)
Usability
9.0
(0 ratings)
10.0
(0 ratings)
Support Rating
9.0
(0 ratings)
-
(0 ratings)
User Testimonials
AWS WAFF5 Distributed Cloud WAF (Web Application Firewall)
Likelihood to Recommend
AWS WAF is highly appropriate to interrupt or prevent cyber attacks because when implementing rules, whether they are specific or centralized, so any application that has these vulnerabilities is protected.
Implementing managed rules creates greater security to protect both API and applications. If implemented along with other AWS tools, the security is much better, so if you want to protect applications against more specific attacks, it is ideal to integrate with Amazon CloudFront, which is a great benefit because it warns when thresholds are exceeded or specific attacks occur. AWS WAF is ideal to avoid common web attacks. For more specific attacks and scenarios, I don't recommend this.
Read full review
It is doing its job effectively, and its scalability is superb. So, if you have a mixed environment with cloud and on-premise systems to protect this product, provide a solution to the challenge. However, its management is more suited to DevOps teams rather than to the ones responsible for on-premise systems, making the management a bit more complex.
Read full review
Pros
  • AWS WAF has the most developer-friendly API to create firewall rules.
  • AWS WAF provides OWASP security controls, which reduces developers' burden (i.e., SQL injection and cross-site scripting).
  • AWS WAF has customizable web security rules. The user can even push the rules through the API available, which is the great feature and helped me a lot.
  • It protects applications at layer 7 (HTTP) of the OSI model and not just layer 4 (TCP).
Read full review
  • Layer seven attacks are becoming far more common. Traditionally it was always layered three, layer four, where you get an additional firewall, but with the application layer attacks become more frequent, more popular, et cetera. So having the web application firewall protecting us, and then with the recent Log4j, that's the most recent use case when it gave us that instant level of protection whilst we remediated the Log4j that we had that and the F5 Distributed Cloud WAF was protecting us.
  • I have a great relationship with the account manager, my account manager, and I think he drives the best price possible, um, for me, and I'm happy with that price.
  • F5 Distributed Cloud WAF is always innovating and evolving.
  • We run a very competitive proof value where we run numerous competitors against each other, and then we evaluate from that and then make the selection, and F5 Distributed Cloud WAF was the winner.
Read full review
Cons
  • The documentation offered is somewhat confusing, so it would be ideal if it were much more direct and precise.
  • Your initial configuration may be confusing, so the best option is to use the rule templates provided by AWS.
  • Its configuration is not unified with AWS, so it must be done separately and it takes some time.
  • The number of rules to be established is somewhat limited.
Read full review
  • Better integration between different F5 solutions
  • Fail over between devices feels unstable if there are thousands of objects attached to the traffic-group. Needs to be more simpler.
  • We have seen issues with malicious user detection where we have used open protocols due to legacy applications, and have been caught with legitimate traffic being blocked.
Read full review
Likelihood to Renew
We have been using AWS WAF for the past 3 years in front of our websites. We find it useful in preventing data crawling, DDOS attacks, etc on our websites, and hence we are going to use it in the future as well. AWS WAF is one of the best Firewalls in business.
Read full review
I would continue using F5 Distributed Cloud WAF because I am highly satisfied with its robust and comprehensive features that effectively protect our applications from evolving cyber threats. The advanced AI capabilities enhance threat detection and response, providing proactive security. Additionally, the excellent customer support ensures quick resolution of any issues, making the overall experience reliable and efficient. Trust in the manufacturer’s innovation and continuous updates further motivates me to keep this solution as a core part of our security infrastructure.
Read full review
Usability
The product is highly scalable. It is easy to configure the rules and thereby helps us to mitigate many vulnerabilities. The interface and programming of the firewall provisions were easy to setup. Amazon clearly spent a lot of time figuring this out and perfecting it. It allows users to do customized configurations based on their needs. It provides protection against a number of security issues like XSS, SQL injection, etc. I would definitely recommend this for protecting your infra as you scale, since this basically protects and filters all requests hitting your application server.
Read full review
I believe is a solution that was designed from the start to be simple and easy to use. Coming from Imperva, it simply eased the burden and complexity of managing and securing our apps on different environments (cloud and on-prem). It easy to scale and very quick to deploy (as a cloud waf should be), provide us with DevOps integrations, visibility and automatic insights from multiple events that guarantee peace of mind for us analysts and opp managers.
Read full review
Reliability and Availability
No answers on this topic
Seems no issue
Read full review
Performance
No answers on this topic
Unnoticed slowness
Read full review
Support Rating
If you're intending to use AWS WAF, I would say that you absolutely should sign up for support. AWS Support is excellent and they can help you in a really good way to solve your issues.
Read full review
I never contacted support for this product.
Read full review
Online Training
No answers on this topic
Online training saves me lots of time
Read full review
Implementation Rating
No answers on this topic
Just make sure you origin servers have F5 IPs allowed.
Read full review
Alternatives Considered
Easy of use. Setup and configuration is fairly quick. There are the usual advantages of it being a cloud solution where you can buy into the solution, configure it and set it up and get it up and running. If you are already a subscriber to AWS, having a native service has its advantages.
Read full review
This plaform has advanced threat detection technology and mitigation of this tool is also great that's why why it helps us in securing from many attacks including damages from 7 attcks, BOTS Mitigations and DDoS Protection. Also this plaform has customised security management policy to tailor security measures according to our specific needs.
Read full review
Scalability
No answers on this topic
Dont see any issue so far
Read full review
Return on Investment
  • Somewhat costly if specific needs are not there.
  • If security is concerned than comparatively is beneficial.
  • All those price that spent on AWS WAF in return gets saved in man hours.
Read full review
  • This helps us quickly push out applications and security to our applications. It is so simple to perform these tasks in F5 Distributed Cloud WAF.
  • We are also using the MSP side of it so we have support and are able to have F5 manage our solutions that can save us time.
Read full review
ScreenShots

F5 Distributed Cloud WAF (Web Application Firewall) Screenshots

Screenshot of Screenshot of