AWS WAF is Amazon's web application firewall, designed to attach directly to AWS entry points: CloudFront distributions, Application Load Balancers, API Gateway, and AppSync. You compose rules from AWS managed rule groups, third-party Marketplace rulesets, or your own custom logic, with rate limiting and geo/IP matching built in.
If you represent AWS WAF, claiming is free and adds a Verified badge to this security profile. Start verification →
Its natural fit is anything already running on AWS, where enabling it is a configuration change rather than a new vendor relationship. Optional paid add-ons (Bot Control, Fraud Control / account-takeover prevention) extend it beyond basic request filtering.
Pricing is pay-as-you-go by the number of rules and requests, which is cost-effective at small scale but needs monitoring at high volume. It protects AWS-fronted apps specifically; it is not a drop-in for a site hosted elsewhere, where an edge WAF like Cloudflare or Fastly is more appropriate.
Category context: Edge and cloud WAF platforms for larger sites and APIs, with managed rules, bot defence, and DDoS at global scale. Usually custom-priced.
The most widely used cloud WAF and CDN, filtering attacks at the DNS edge before they reach your origin.
Compare →The Signal Sciences engine on Fastly's edge, protecting web apps and APIs with low-friction, threshold-based blocking.
Compare →Microsoft's WAF on Azure Front Door and Application Gateway, with managed OWASP rulesets.
Compare →AWS WAF is Amazon Web Services' web application firewall. It attaches to AWS entry points (CloudFront, Application Load Balancer, API Gateway, AppSync) and filters traffic using AWS managed rule groups, Marketplace rulesets, or custom rules, with rate limiting and geo/IP matching. It is billed pay-as-you-go.
AWS WAF uses pay-as-you-go pricing based on the number of web ACLs and rules you deploy plus the number of requests inspected. Advanced features like Bot Control and Fraud Control are priced as separate add-ons. Costs are low at small scale but should be monitored on high-traffic applications.
AWS WAF is designed to protect applications fronted by AWS services, so it is not a general drop-in for a site hosted elsewhere. If your site is not on AWS, an edge WAF such as Cloudflare or Fastly, which sit in front of any origin via DNS, is the better fit.
HostList is independent. This profile is editorial; HostList accepts no sponsorship, affiliate commission, or paid placement from AWS WAF or any security vendor.