AWS native WAF can be easily integrated with Application Load Balancer with which we can allow Internet bound Inbound traffic directly on ALB. Same ALB can be protected by AWS Shield, with this we can achieve DDoS L3, L4 & L7 protection. Also AWS WAF supports third party vendor managed rules i.e. F5, Imperva etc to add in WEB ACL Review collected by and hosted on G2.com.
AWS managed WAF rules has limitations of protecting against OWASP top 10 attack pattern i.e. if you change SQL injection attack pattern, AWS Managed WAF rules failed to block it. AWS needs to work on such sort of things. Review collected by and hosted on G2.com.
AWS WAF is the web based firewall which has built-in DDOS attack protection to stop any DDOS attacks. Also, the AWS support team quickly responds to the queries or concerns raised. Review collected by and hosted on G2.com.
There is no dislike about AWS WAF as it has good features. Review collected by and hosted on G2.com.
We are using AWS WAF for securing our e-learing web applcation where we have defiened webACL rules to block unwanted traffic which can be suspicious. quite easy to impliment also provides live monitoring of traffic and can be connected with other aws services like aws cloudwatch using which user can monitor and analyze traffic. Review collected by and hosted on G2.com.
I don't think their is much to dislike about AWS WAF but still implementation can be time consuming, other than that it's one of the best web application firewall which offers pay as you go pricing. Review collected by and hosted on G2.com.
We can set a standard of rules and because of this we can save time even though it has great inbuilt rules. It has a easy tracking and managing bots and blocking of bots function. Review collected by and hosted on G2.com.
It is a good product but a bit expensive compared to its peers and also end to end encryption for multi customer are issue. Review collected by and hosted on G2.com.
Easily configure WAF to filter, monitor and block any malicious traffic traveling to the web application and API Gateways ensuring the traffic is safe and identify and stop any malicious traffic Review collected by and hosted on G2.com.
it is not possible to extend AWS WAF for applications built outside AWS (on-premise or any other cloud). AWS WAF cannot be deployed directly to EC2 instances and can only be associated with ALB , CloudFront & API Gateway Review collected by and hosted on G2.com.
AWS WAF is a pay-as-you-go service so we will pay for what we use this is scalable reliable and easy to use. We continue using the CLI Command line interface, which does not require GUI. Review collected by and hosted on G2.com.
If is it pay as you go service this will be expensive for high-traffic websites and it will generate a lot of traffic where the bill spikes will be high and expensive Review collected by and hosted on G2.com.
Very easy to deploy and configure. There are managed rules and custom rule creation. Review collected by and hosted on G2.com.
Log should contain more details about attack type and reason for block. Review collected by and hosted on G2.com.
This helps to prevent any attacks on application and since it is AWS managed service it reduces the effort to setup. Review collected by and hosted on G2.com.
This brings cost
False positives like any other security system.
Setup is complicated. Review collected by and hosted on G2.com.
Organization and progression of key elements needed to build your WAF. The rules engine is easy to implement. Review collected by and hosted on G2.com.
I dislike that I have to do this, but its a necessary evil Review collected by and hosted on G2.com.