Listing Thumbnail

    CloudGuard WAF

     Info
    Deployed on AWS
    Are you looking for an automated Web Application Firewall (WAF) with precise prevention and no management overheads? CloudGuard WAF delivers AI-enabled Web Application and API protection.

    Overview

    Play video

    With deep application contextual analysis, CloudGuard WAF eliminates the tradeoff between the level of application security and the complexity of managing it. Your applications drive your business. As they evolve, grow, and expose more APIs, your attack surface expands. CloudGuard WAF learns how an application is typically used by profiling the user and the app content. It then scores each request accordingly, eliminating false positives while maintaining the highest security standards. CloudGuard WAF is easy to deploy and requires no ongoing maintenance as it continues to protect your evolving applications and APIs.

    Advantages

    • 90% of CloudGuard WAF customers run in prevent mode, demonstrating the hands-off nature of the management required
    • 100% of CloudGuard WAF customers have less than 10 exception rules!
    • CloudGuard WAF goes from deployment to active protection in just days, not weeks.

    Click on the "View Usage Instructions" and "Usage Information" below to get next steps for setting up CloudGuard WAF.

    This is a BYOL Image. Pricing and entitlements for this product are directly with Check Point. As an AWS partner Check Point enables marketplace transaction on this listing through a private offer provided by Check Point. Please contact your Check Point trusted advisers (link to a list of CP sellers / or directly to check point SDRs). Payment for the underlaying infrastructures are paid directly to AWS and is based on AWS pricing.

    Highlights

    • Precise Prevention: Contextual app analysis for high fidelity application security to prevent known and unknown cyberattacks.
    • Automated by Design: Auto-deploy, hands-off management and AI-powered short learning cycles.
    • Flexible deployment: Protect all applications in any cloud environment built on any architecture.

    Details

    Delivery method

    Delivery option
    Auto Scaling Group
    Single Gateway into existing VPC
    Single Gateway into new VPC

    Latest version

    Operating system
    OtherLinux Gaia 3.10

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CloudGuard WAF

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Please see seller website for refund details.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Auto Scaling Group

    A number of AppSec instances in an Auto Scaling Group. Load balanced by an ELB.

    CloudFormation Template (CFT)

    AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."

    Additional details

    Usage instructions

    Navigate to https://portal.checkpoint.com ; if you do not have an existing account, open a new account. Open the main menu (icon is in the top left corner), choose APPLICATION SECURITY under the CloudGuard column, then select Cloud on the left. The Getting Started page will open. After defining the asset, you will be redirected to the Profile page. Note: Obtain the Token for CloudGuard WAF from the Profile page.

    Support

    Vendor support

    To open a support ticket, send an email to infinity-next-support@checkpoint.com  CloudGuard WAF

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.1
    4 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    4 AWS reviews
    |
    55 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Anshika B.

    Check Point CloudGuard WAF

    Reviewed on Oct 13, 2025
    Review provided by G2
    What do you like best about the product?
    Checkpoint CloudGuard WAF is a great solution. It uses contextual AI/ML based threat prevention to stop both known threats and zero-day attacks without need for constant signature updates. From a deployment and operation viewpoint, CloudGuard WAF shines, it is cloud-native, Supports infrastructure as a code/API-based setup. Customer support is so great. We have achieved all our use cases.
    What do you dislike about the product?
    No dislike as of now. We liked that product.
    What problems is the product solving and how is that benefiting you?
    CloudGuard WAF addresses the challenges posted by traditional WAFs that rely heavily on static signatures, manual rule tuning and reactive defences. It also improves detection accuracy while dramatically reducing false positives, so your security operation teams spend much time investigating benign traffic and more time responding to real threats. Additional features like built in bot detection, DDos mitigation, and file upload scanning further close off common attack vectors.
    Maaz Patel

    Automated protection has minimized manual effort and improved cloud workload security

    Reviewed on Oct 13, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Our main use case for Check Point CloudGuard WAF  involves sharing, conferencing, and comprehensive detection. We also use the cloud native integration for seamless integration in major cloud platforms such as AWS , Azure , and Google Cloud .

    One specific example of how we use Check Point CloudGuard WAF  in those cloud environments is for advanced ruling. While the platform offers robust protection, we utilize it for protection while fine-tuning advanced policies. We also sell it to smaller organizations with limited accessibility and adoption.

    We primarily use Check Point CloudGuard WAF  for its features because Check Point offers many different capabilities and simplicity in policy management and security visibility, so the advanced state of this is always simplicity and its features.

    What is most valuable?

    The best features that Check Point CloudGuard WAF  offers include cloud native integration with seamless integrations and automated management, which offers hands-off operation. Approximately 90% of customers are operating in preventive mode, eliminating the need for constant fine-tuning.

    The automated management assists our team with automatic scaling since CloudGuard can automatically scale with other cloud workloads. During traffic spikes, it can handle additional load without manual intervention, ensuring consistent protection. Additionally, there's unified management across the cloud and seamless integration with deployed pipelines.

    The implementation of Check Point CloudGuard WAF has positively impacted our organization by increasing our security significantly. We have a faster and smarter CloudGuard that provides strong security.

    I've noticed improvements in our web application security, as the solution integrates seamlessly with the cloud infrastructure and provides automated protection against common threats, which are reduced, and our manual workload is simplified.

    What needs improvement?

    I would add a feature for fast threat response, because with direct integration into cloud native services such as load balancers, storage, and APIs, it can detect and block threats immediately at the source.

    Currently, there are no features I wish worked better or would to see added in Check Point CloudGuard WAF.

    For how long have I used the solution?

    I have been working as a network security engineer for two years in my career.

    What other advice do I have?

    My advice for others looking into using Check Point CloudGuard WAF is to plan your deployment carefully, leverage the cloud native integration, invest time in training, and continuously monitor and optimize.

    We are partners with this vendor, besides being a customer.

    I rate Check Point CloudGuard WAF 10 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Sidharth M.

    Checkpoint Cloudguard WAF

    Reviewed on Oct 10, 2025
    Review provided by G2
    What do you like best about the product?
    Checkpoint CloudGuard WAF is appreciated for its intelligent,prevention first approach to securing web application and API's. It offers comprehensive suite of protection, including bot mitigation, DDoS defence, file reputation check and coverage for thousands of known vulnerabilities.Beyond its technical strengths, Checkpoint CoudGuard WAF Excels in delivering a seamless user experience. customer support is so great.
    What do you dislike about the product?
    Some users have also noted that documentation can be more user-friendly. Other than this solution is so greta.
    What problems is the product solving and how is that benefiting you?
    One of the biggest problems it solves is the detection and prevention of zero-day attacks and OWASP top 10 vulnerabilities with relying on signature update. A common pain point with traditional WAFs that generate excessive false positive. CloudGuard's cloud-native design and support for infrastructure-as-code streamline deployment and integration into CI/CD pipelines.
    Ankit K.

    Checkpoint CloudGuard WAF

    Reviewed on Oct 06, 2025
    Review provided by G2
    What do you like best about the product?
    What I like most about Checkpoint cloud guard WAF is it combine, AI-Driven protection with simplicity of deployment and low operational burden. The solution is cloud native, scalable, globally distributed and designed for rapid deployment so organization can protect their web assets quickly. Checkpoint Cloud Guard WAF uses contextual AI to defend web apps and APIs from known and zero-day threats, with minimal false positive and no manual tunning. Customer support is very active.
    What do you dislike about the product?
    There is no dislike as of now. Product is doing great.
    What problems is the product solving and how is that benefiting you?
    CloudGuard's machine learning engines detect behavioral anomalies and uses both supervised and unsupervised learning to find threats without waiting for signature updates. Reduced noise and fewer false alarm - less time wasted investigating false positive. Better compliance- enhanced visibility and reporting help show where protections are in place. Deployment is fast and scalable, integrating with cloud-native environments, means protection can go live quickly.
    reviewer2751468

    Robust threat protection improves security and operational efficiency

    Reviewed on Sep 04, 2025
    Review from a verified AWS customer

    What is our primary use case?

    Our main use case for Check Point CloudGuard WAF  is to protect web applications and APIs from common threats such as SQL injection, cross-site scripting, and bot attacks.

    A specific example of how we've used Check Point CloudGuard WAF  to protect against SQL injection attempts is that we had a public-facing customer portal hosted on AWS , where CloudGuard WAF  detected and logged multiple SQL injection attempts targeting the login page and flagged the attacks in real time. We were able to review detailed logs showing the malicious payload, which ensured the application stayed fully available without any downtime and prevented the exposure of sensitive data, giving our security team confidence that the WAF  rules were working efficiently against the OWASP Top 10 threats.

    How has it helped my organization?

    Check Point CloudGuard WAF has positively impacted our organization in security and operational efficiency. Our critical web apps and APIs are now continuously protected against the OWASP Top 10 threats, and we have seen fewer phishing exploit attempts after deploying, with a 30-40% drop in malicious traffic and a 15-20% reduction in manual intervention for our SOC team due to reduced false positives and automated protection.

    By blocking attacks automatically at the WAF layer, we have reduced the incidents escalated to our SOC team by around 30-35%, and the application team no longer needs to push urgent code changes to mitigate vulnerabilities. The WAF policies buy them time, saving several hours per incident, and with fewer false positives and reduced noise, we have avoided the need to hire additional headcount for web app monitoring.

    What is most valuable?

    Some of the standout features of Check Point CloudGuard WAF that help with our main use case are contextual machine learning-based WAF, including the OWASP Top 10 API-based protection and discovery, anti-bot protection, intrusion prevention and CVE coverage, file security, DDoS and rate limiting.

    The contextual machine learning-based protection of Check Point CloudGuard WAF works effectively for most teams because it goes beyond the static signature and regex-based detection that traditional WAFs rely on. Compared to older WAFs, we have noticed clear differences, such as smarter detection of novel attacks thanks to the ML engine and lower false positives, meaning the legitimate traffic isn't blocked as often, and we experience faster onboarding for new apps, allowing us to spend less time tuning the policies.

    What needs improvement?

    Areas where Check Point CloudGuard WAF can improve include simple policy tuning, as the protection seems strong, though initial rule tuning can be complex. More guided workflows or templates would help speed up deployment, along with deeper integration with the DevOps pipeline, and while it handles API well, more dedicated API security would add value.

    In addition, it could be improved with better integration with the DevOps pipeline, more granular reporting, as the dashboards provide good high-level visibility, but sometimes digging into specific attack patterns or trends requires manual effort, and simple tuning of the ML models would be beneficial.

    For how long have I used the solution?

    I have been using Check Point CloudGuard WAF for around a year.

    Which solution did I use previously and why did I switch?

    Before adopting Check Point CloudGuard WAF, we were using the AWS  native WAF for some workloads and Imperva WAF in certain environments, which provided baseline protection but were found too limited in advanced threat protection.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that the pricing and licensing seem fair but not the simplest, as the licensing is flexible and subscription-based. While it can feel complex to estimate the upfront cost depending on traffic volume and features enabled, the initial setup cost is straightforward with minimal infrastructure costs, though fine-tuning and integrating took extra time, which adds to the indirect setup cost in terms of experienced resources.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Check Point CloudGuard WAF.

    What other advice do I have?

    I would rate Check Point CloudGuard WAF an 8 out of 10.

    I chose the 8 because Check Point CloudGuard WAF provides robust protection, great cloud integration, and effective ML-based threat detection, which has improved our AppSec posture, but it isn't a 9 or 10 yet because the policy tuning can be complex, advanced API protection feels limited, and the learning curve is somewhat steep for new administrators.

    My advice for those looking into using Check Point CloudGuard WAF is to plan your deployment strategy early, especially whether to run it in a single cloud or across different environments, as that impacts the setup.

    My company has a business relationship with Check Point, as we are a partner.

    I was not offered a gift card or incentive for this review.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews