AWS-native web application firewall

AWS WAF

A managed AWS web application firewall using web ACLs, rules, rule groups, request inspection, and actions across supported AWS resources.

Editorial verdict

Choose AWS WAF when supported AWS resource placement and account governance dominate, and the team can own rule selection, capacity, tuning, logging, and false positives.12

Best for

  • Supported AWS delivery and application resources
  • AWS account and policy governance
  • Managed and custom web ACL rules
12

Not ideal for

  • Non-AWS traffic estates
  • Provider-neutral edge controls
  • Teams expecting managed rules to remove tuning and remediation
12
Main trade-off

AWS-native integration reduces handoffs while request, ACL, rule, logging, managed-rule, capacity, tuning, regional, and adjacent-service costs remain explicit.12

Product boundary

Whether AWS-native placement, rule groups, logging, and account governance are the right WAF control plane.

AWS WAF protects supported AWS resources through web ACLs and rules. Shield, Firewall Manager, CloudFront, ALB, API Gateway, AppSync, Cognito, logs, Marketplace rule groups, Bot Control, Fraud Control, and CAPTCHA have separate behavior and cost boundaries.12

For: Teams protecting supported AWS resources and governing security controls through AWS

  • Protected traffic is outside supported AWS resources
  • Another edge platform is already authoritative
  • Rule, log, feature, or regional cost changes the fit

Why teams consider AWS WAF

  • AWS resource integrationWeb ACLs attach to supported CloudFront, load-balancing, API, GraphQL, and identity surfaces.12
  • Rule ecosystemCustom, AWS managed, and Marketplace rule groups support different operating models.12
  • Governance integrationAWS account, logging, IAM, and Firewall Manager patterns can govern the control.12

Pricing

AWS WAF charges by web ACL, rules or rule groups, and processed requests; managed Marketplace rules, Bot Control, Fraud Control, CAPTCHA, Challenge, logs, protected AWS resources, and regions can add charges.2

Current decision boundary

Usage-based AWS service

Verified 2026-07-27: AWS WAF meters web ACLs, rules, rule groups, and requests with separate charges for optional security features, logs, Marketplace content, and protected AWS services.2

Primary meters
Web ACLs, rules or rule groups, and requests2
Optional charges
Marketplace rules, Bot Control, Fraud Control, CAPTCHA, Challenge, and logs2
Adjacent services
CloudFront, ALB, API Gateway, AppSync, Cognito, Shield, and regional usage2
Pricing checked View official pricing

AWS WAF vs alternatives

Cloudflare WAF

Choose when
Cloudflare-proxied web and API traffic
Avoid when
Traffic that bypasses Cloudflare
Compared with AWS WAF
Edge rules can reduce exposure while introducing false positives, tuning, plan gates, provider-specific expressions, logging, and bypass considerations.34

Fastly Next-Gen WAF

Choose when
Fastly-aligned application security
Avoid when
Small applications needing a simple cloud-native WAF
Compared with AWS WAF
Managed security operations can reduce rule-program burden while adding contract, deployment, tuning, telemetry, integration, and provider dependence.56

Resources and sources

Official product, pricing, policy, and operating sources

  • AWS WAF documentation
    Open
  • AWS WAF pricing
    Open
  • Cloudflare WAF overview
    Open
  • Cloudflare application services plans
    Open
  • Fastly Next-Gen WAF documentation
    Open
  • Fastly pricing
    Open
  1. 1
    AWS WAF documentation

    AWS · Accessed Official

  2. 2
    AWS WAF pricing

    AWS · Accessed Official

  3. 3
    Cloudflare WAF overview

    Cloudflare · Accessed Official

  4. 4
    Cloudflare application services plans

    Cloudflare · Accessed Official

  5. 5
    Fastly Next-Gen WAF documentation

    Fastly · Accessed Official

  6. 6
    Fastly pricing

    Fastly · Accessed Official