Security
Web Application Firewalls
Choose managed HTTP request filtering by traffic path, rule ownership, false-positive control, observability, and incident operations.
Recommendation
Use the WAF on the traffic platform the team can observe and operate.
Choose the control and ownership model
Start from the threat, protected asset, evidence obligation, or enforcement point before comparing products.
Decision routes
Each route addresses a bounded security job and retains an explicit verification and failure boundary.
Cloudflare is authoritative for application edge traffic
Evaluate Cloudflare WAF.
Cloudflare WAF is the edge route when managed and custom rules should execute within an existing Cloudflare application-delivery boundary.
Verify: Verify DNS and proxy coverage, rulesets, overrides, exceptions, logging, false positives, origin bypass, plan entitlements, request pricing, and incident workflow.1
HTTP applications are protected through supported AWS resources
Evaluate AWS WAF.
AWS WAF is the AWS-native route when web ACLs, managed or custom rules, logging, and supported AWS application resources form the operating boundary.
Verify: Model resource association, rule capacity, managed groups, exceptions, bot or fraud add-ons, logs, labels, false positives, requests, and AWS account ownership.2
Fastly's managed WAF deployment and operations model fits
Evaluate Fastly Next-Gen WAF.
Fastly Next-Gen WAF is the specialist managed route when its deployment options, rule and signal model, and Fastly operating workflow match the application.
Verify: Verify deployment placement, agents or edge coverage, rules, thresholds, exceptions, telemetry, false positives, support, pricing, and origin bypass.3
Boundary: A WAF applies HTTP request rules; Bot Protection evaluates automated actors, Rate Limiting enforces quota, and Vulnerability Scanning detects weaknesses that still require remediation.
Differences that change the control
Compare enforcement, evidence, operating ownership, failure behavior, sensitive-data exposure, and exit rather than marketing breadth.
- Placement
- Edge network, cloud resource, and specialist deployment models see different traffic and create different bypass paths.3
- Rule lifecycle
- Managed rules, custom logic, updates, capacity, exclusions, thresholds, and staging affect both coverage and false positives.12
- Evidence
- Match context, logs, payload handling, retention, alerts, and investigation access determine whether teams can operate the control.3
Official resources
Verify current control boundaries, telemetry or evidence handling, deployment, limits, pricing, policy, and operating responsibilities in first-party material.
Related tools
Sources
Official documentation supports product boundaries and verification points; the route recommendation remains a bounded editorial judgment.
- 1Cloudflare WAF documentation
Cloudflare · Accessed Official
- 2AWS WAF developer guide
Amazon Web Services · Accessed Official
- 3Fastly Next-Gen WAF documentation
Fastly · Accessed Official
- 4NIST Secure Software Development Framework
NIST · Accessed Official
- 5AWS WAF pricing
Amazon Web Services · Accessed Official