AWS WAF logo

AWS WAF

Enterprise WAFUnverified

AWS WAF is Amazon's web application firewall, designed to attach directly to AWS entry points: CloudFront distributions, Application Load Balancers, API Gateway, and AppSync. You compose rules from AWS managed rule groups, third-party Marketplace rulesets, or your own custom logic, with rate limiting and geo/IP matching built in.

Visit AWS WAF ↗← All security solutionsClaim this listing →
Profile unclaimed

If you represent AWS WAF, claiming is free and adds a Verified badge to this security profile. Start verification →

Category
Enterprise WAF
Best for
AWS-hosted apps and APIs
Pricing
Pay as you go (per rule + per request); add-ons extra
Founded
2015 (AWS)

HOW IT WORKS

Its natural fit is anything already running on AWS, where enabling it is a configuration change rather than a new vendor relationship. Optional paid add-ons (Bot Control, Fraud Control / account-takeover prevention) extend it beyond basic request filtering.

Pricing is pay-as-you-go by the number of rules and requests, which is cost-effective at small scale but needs monitoring at high volume. It protects AWS-fronted apps specifically; it is not a drop-in for a site hosted elsewhere, where an edge WAF like Cloudflare or Fastly is more appropriate.

Category context: Edge and cloud WAF platforms for larger sites and APIs, with managed rules, bot defence, and DDoS at global scale. Usually custom-priced.

WHAT IT DOES

  • Managed rule groups (AWS and Marketplace vendors)
  • Custom rules, rate limiting, and geo/IP match
  • Bot Control and account-takeover prevention (add-ons)
  • Native integration with CloudFront, ALB, API Gateway

BEST FOR

  • Applications already hosted on AWS
  • Teams wanting WAF managed as infrastructure-as-code
  • APIs behind API Gateway or CloudFront

ALTERNATIVES TO AWS WAF

Cloud WAF
Cloudflare

The most widely used cloud WAF and CDN, filtering attacks at the DNS edge before they reach your origin.

Compare →
Enterprise WAF
Fastly Next-Gen WAF

The Signal Sciences engine on Fastly's edge, protecting web apps and APIs with low-friction, threshold-based blocking.

Compare →
Enterprise WAF
Azure WAF

Microsoft's WAF on Azure Front Door and Application Gateway, with managed OWASP rulesets.

Compare →

AWS WAF FAQ

What is AWS WAF?

AWS WAF is Amazon Web Services' web application firewall. It attaches to AWS entry points (CloudFront, Application Load Balancer, API Gateway, AppSync) and filters traffic using AWS managed rule groups, Marketplace rulesets, or custom rules, with rate limiting and geo/IP matching. It is billed pay-as-you-go.

How much does AWS WAF cost?

AWS WAF uses pay-as-you-go pricing based on the number of web ACLs and rules you deploy plus the number of requests inspected. Advanced features like Bot Control and Fraud Control are priced as separate add-ons. Costs are low at small scale but should be monitored on high-traffic applications.

Does AWS WAF work for non-AWS sites?

AWS WAF is designed to protect applications fronted by AWS services, so it is not a general drop-in for a site hosted elsewhere. If your site is not on AWS, an edge WAF such as Cloudflare or Fastly, which sit in front of any origin via DNS, is the better fit.

Editorial independence

HostList is independent. This profile is editorial; HostList accepts no sponsorship, affiliate commission, or paid placement from AWS WAF or any security vendor.