Radware Cloud WAF is a fully managed Cloud Application Protection Service providing the industry's most comprehensive web application security solution. It integrates Radware's cloud-delivered WAF technology, API protection, Bot management, application layer DDoS protection, client-side protection, analytics, threat detection and security feeds in a single portal.
Radware Cloud WAF is a fully managed Cloud Application Protection Service providing the industry's most comprehensive web application security solution. The service integrates Radware's Cloud WAF, API Protection, Bot management, client-side and application layer DDoS protection in a single portal that provides security analytics, threat detection and real-time security feeds to protect applications against hacking, malicious bots, API exposure, Web DDoS attacks, supply chain attacks and other vulnerabilities.
Radware's combination of negative and positive security models provides a complete level of protection against OWASP Top 10 threats and zero-day attacks.
API Discovery and Protection - End-to-end API solution from Discovery to protection at a click of a button. Radware auto API discovery maps all of your applications documented and undocumented third-party APIs, automatically generates Open API schema files, generates tailored security policies to detect and block API-focused attacks in real time and enforce protection across all your APIs. Radware's advanced API protection eliminates your documenting and protecting APIs overheads and keeps your organization protected across the board.
Bot Management - Integrated Bot Manager provides comprehensive mitigation options, such as Blockchain-based Crypto challenges to counter attacks. It ensures precise bot management for web, mobile, and API traffic by employing behavioral modeling, collective bot intelligence, and fingerprinting. This defense guards against all OWASP 21 automated threats, including account takeover, credential stuffing, DDoS, fraud, and web scraping, fortifying online operations.
Web DDoS Protection - Industry leading application-layer L7 protection against DDoS attacks, based on Radware's unique machine-learning-based behavioral detection that distinguishes between legitimate and malicious traffic, and automatically generates granular signatures in real-time to protect against zero-day attacks. Best-in-class security against a wide variety of threats, including HTTP Floods, HTTP bombs, low-and-slow assaults, Brute Force attacks, and disruptive web DDoS Tsunamis.
Client-side Protection - Easily block requests to suspicious third-party services in your supply chain and adhere to data security compliance standards. Protect against client-side attacks coming from third party JS services - Formjacking, Skimming,Magecart, automatically and continuously discover all third-party services in your supply chain with detailed activity tracking, as well as get alerts & threat level assessment according to multiple indicators, including script source and destination domain.
Pricing
We have 3 different pricing packages - Standard, Advanced and Complete. The Standard and Advanced packages come with some of the features while Complete provides full coverage.
Highlights
Fully Managed Web Application Protection Service - 24x7 Fully managed security service by Radware's expert Emergency Response Team(ERT). Protect Against OWASP Vulnerabilities - Stay protected against 150+ known attack vectors, including the OWASP Top 10 Web Application Security Risks, Top 10 API Security Vulnerabilities, Top 21 Automated Threats To Web Applications, and Top 10 Client-side vulnerabilities
Detect, Manage and Mitigate Bots - Detect and distinguish between good and bad bots to protect websites, mobile apps and APIs. Easily optimize and customize your bot management policies to provide a better user experience and drive more ROI from your application traffic. End-to-end API Protection - From discovery to enforcement at a click of a button, Radware combines behavioral analysis and policy automation to protect from increasingly sophisticated API assaults.
Mitigate Application-Level DDoS Assaults - Radware's DDoS protection technologies provide the shortest time to detection and mitigation of most advanced and high volume HTTP-based DDoS assaults by utilizing patented behavioral analysis, machine learning-based engines. Protect Client-Side From Supply Chain Attacks - This solution offers advanced client side protection that ensures the protection of end users data when interacting with any third-party services in the application supply chain.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is usage-based and measured in Mbps of legitimate bandwidth. You start with a base Cloud Application Protection plan in three levels: Standard, Advanced, and Complete. Standard sizes by throughput (10, 50, or 100 Mbps) for one application. Advanced and Complete cover 10 Mbps for one application, with per-application add-ons to expand coverage. On top of any base plan, you can layer independent add-ons billed separately. These include CDN enablement, Cloud DDoS Protection (on-demand or always-on), Web DDoS, Firewall as a Service, Network Analytics, AI SOC Xpert, Access Logs, LLM Firewall, PCI DSS compliance, ERT Premium support, extra protected networks, and the SecurePath connector.
Top-of-mind questions for buyers
What does one Mbps of legitimate bandwidth mean for billing?
Pricing meters legitimate traffic bandwidth, measured in Mbps, not attack or blocked traffic. Your base plan is sized to a bandwidth tier, and many add-ons are also priced against legitimate bandwidth blocks, such as 10Mbps or 200Mbps units. Attack traffic that the service filters out does not count toward your metered bandwidth.
How do the base plan and add-ons combine on one bill?
You pick one base Cloud Application Protection plan, then layer optional add-ons that each bill separately. Charges add together, so your total is the base plan plus every add-on you select. Per-application add-ons extend coverage one application at a time. Bandwidth-based add-ons bill in fixed blocks, like 10Mbps or 200Mbps.
How do the On-Demand and Always-On Cloud DDoS Protection options differ for cost?
Both meter legitimate bandwidth in 10Mbps units. On-Demand DDoS Protection engages only when mitigation is triggered, suited to occasional attack response. Always-On keeps protection active continuously, suited to constant exposure. You choose one model per subscription, and each is billed monthly against your legitimate bandwidth.
www.radware.com
Helpful?
Vendor refund policy
No refund offered
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Online Support Service Portal -Appropriate for non-critical issues, such as general inquiries, requests for technical documentation/ information, schedule support during an upcoming maintenance window, view installed base and manage support cases.24x7, where Internet service is available
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Alteon VA supports the complex functionality requirements of Enterprise applications which go beyond basic availability and quality of experience features. These include: Layer 7 Rewrite, Application Level Traffic Steering, Caching, SSL Offload, compression, acceleration. WAF (AppWall), SecureUR L
Cloud Native Protector provides an agentless, cloud-native solution for comprehensive protection of AWS assets, to protect both the overall security posture of cloud environments, as well as protect individual cloud workloads against cloud-native attack vectors
Radware Bot Manager offers robust defense for web apps, mobile apps, and APIs against automated threats through layered defenses. It guards against various risks like account takeover, DDoS, web scraping, etc. The solution provides multiple mitigation choices, including the innovative Crypto Challenge, granting genuine users CAPTCHA-free access while thwarting bot assaults. It also secures native iOS/Android apps, ensuring swift protection against identity spoofing, tampering, and replay attacks, while blocking unauthorized access from emulators and modified systems.
Web protection has reduced municipal incidents and provides clear visibility into global attacks
Reviewed on Sep 02, 2026
Review from a verified AWS customer
What is our primary use case?
Radware Cloud WAF Service is a tool for controlling the websites of the Municipio de Quito, and I have significant visibility with the tool.
For example, on two principal sites of Quito, I have implemented geo-blocking policies, and I can detect attacks from China, Russia, and other locations. I have visibility for these attacks, and this is a fundamental tool to protect the municipality.
How has it helped my organization?
Radware Cloud WAF Service has positively impacted my organization by stopping attacks such as SQL injection attacks and geo-blocking attacks, which appear frequently in the tool logs.
I have experienced a reduction of incidents in my organization since we started using it.
What is most valuable?
I use a WAF which stands out as one of the best features Radware Cloud WAF Service offers.
It is focused on web services, and the API is a very recent proof of concept; I do not currently have features for web services. With Radware Cloud WAF Service, strong behavior, threat detection, and automated policy synchronization are features that could make it even better. I also observe DDoS protection and visibility of the forwarding and system logs.
I assess Radware Cloud WAF Service for blocking unknown threats and attacks, primarily with threats such as geo-blocking and OWASP compliance, as well as SQL injection. I do not currently see other threats in the logs.
What needs improvement?
Radware Cloud WAF Service is easy to use, and configuring and monitoring the logs is straightforward.
I do not currently have integration with a SIEM, but I have a SIEM integration planned for the next two months as I implement new tools to complete my cybersecurity area.
To reduce false positives from geo-blocking, I maintain a list of public IPs. I currently experience many false positives with my front-end firewall, as I do not have a geo-blocking solution in this firewall, but I have reduced these false positive issues.
For how long have I used the solution?
I have been working in my current field for almost three years.
What do I think about the stability of the solution?
I do not have anything to add about my main use case or how I interact with Radware Cloud WAF Service. I have a proof of concept for APIs in Radware Cloud Services, but it is not yet complete.
What do I think about the scalability of the solution?
I am currently only integrating this and have no other implementation.
How are customer service and support?
I work with a partner; my company does not have a business relationship with this vendor other than being a customer.
Which solution did I use previously and why did I switch?
I do not have additional thoughts about Radware Cloud WAF Service.
How was the initial setup?
The integration is simple and easy with my sites.
What about the implementation team?
The purchase is not directly through a partner; I work with two partners, and they purchased and passed the licenses to the government entity.
What was our ROI?
It is easy for my team, and it has reduced incidents.
What's my experience with pricing, setup cost, and licensing?
I have a process to purchase additional features or services for Radware Cloud WAF Service.
Which other solutions did I evaluate?
I have the configuration for SIEM logs, and I need to complete the proof of concept of the API Discovery Automate.
What other advice do I have?
The advice I would give to others looking into using Radware Cloud WAF Service is that it is a tool for my business.
Radware Cloud WAF Service remains a great solution that shines in high-security, high-throughput environments where behavioral detection and hybrid multi-cloud deployment flexibility are top priorities. My overall rating for this review is ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
reviewer2894466
Web protections have prevented breaches and currently secure hundreds of critical applications
Reviewed on Aug 31, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for Radware Cloud WAF Service is protecting web application servers, as I am protecting 750 applications or more. Radware Cloud WAF Service protects the perimeter or the front end of the web applications, so I am using all the protections it comes with. I have nothing else to add about my main use case or how I am using Radware Cloud WAF Service.
What is most valuable?
The best features Radware Cloud WAF Service offers are the custom signatures and the API protection. The custom signatures and API protection have helped me because other vendors don't have API protection, so that's a significant advantage. Radware was chosen by Caterpillar because Radware is bleeding edge cybersecurity, though I was not at the company when these decisions were made.
Radware Cloud WAF Service has positively impacted my organization by keeping us from having data breaches or denial of service attacks, which is the positive outcome of using the WAF. I don't really track the positive outcomes; management tracks more of the failures than the positives, and that's not my area, so I can't really comment.
What needs improvement?
I wish I had normalization because Radware Cloud WAF Service is not normalizing inputs properly and that's causing a lot of problems. Radware Cloud WAF Service can be improved as the unified portal is still buggy and mutual TLS needs to be enhanced because it only performs server side, and it needs to be client side. I've put in an NFR for that, so Radware knows about it.
Regarding Radware Cloud WAF Service's AI capabilities, I think it needs more work as the AI makes a lot of mistakes. I've already commented on that; the governance and security is fine, but the accuracy is lacking. I assess Radware Cloud WAF Service for blocking unknown threats and attacks by saying it depends; if the signatures are up to date and its positive model is working properly, it's very good, but the problem is its normalization is broken, so Radware Cloud WAF Service can be bypassed quite a bit if you know what to look for, and this is a problem, which is why normalization needs to be fixed.
I don't know if Radware Cloud WAF Service has helped reduce my false positives; I can't answer that as it seems to have more false positives than F5 from my experience. I assess Radware Cloud WAF Service's ability to protect against zero-day attacks by saying it depends on the zero-day attack; if it's a web DDoS, it protects fine, but if it's something else, how would I know, because the definition of a zero day is you don't have any protection for it.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for about two and a half years.
What do I think about the stability of the solution?
Radware Cloud WAF Service seems to be stable.
What do I think about the scalability of the solution?
The scalability of Radware Cloud WAF Service seems adequate.
How are customer service and support?
The customer support is not bad. I would rate the customer support an 8 on a scale of 1 to 10.
How was the initial setup?
I don't know how Radware Cloud WAF Service is deployed; I assume it's private cloud.
What was our ROI?
I haven't seen a return on investment from using Radware Cloud WAF Service, and I can share that Caterpillar is not that smart.
What's my experience with pricing, setup cost, and licensing?
I have no comment on my experience with pricing, setup cost, and licensing as I have nothing to do with any of that.
Which other solutions did I evaluate?
I cannot comment on whether I evaluated other options before choosing Radware Cloud WAF Service, as I was not here when those evaluations took place.
What other advice do I have?
I can't say whether there are any other improvements Radware Cloud WAF Service needs beyond what we've discussed. I assess Radware Cloud WAF Service for integrating with other systems and applications in my environment by saying it seems to integrate fine through the APIs, so it doesn't seem to be an issue there. I'm not using the API discovery feature at this time. I don't have any advice to give to others looking into using Radware Cloud WAF Service. I would rate this product an 8 overall.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
reviewer2894385
Protection has ensured continuous web availability and now lets us focus on core financial services
Reviewed on Aug 31, 2026
Review provided by PeerSpot
What is our primary use case?
The product is used for the protection of our financial institution’s web applications and digital assets against DDoS attacks and other OWASP threats.
How has it helped my organization?
Radware gives us greater confidence in the availability and security of our assets, allowing our team to focus less on infrastructure protection and more on our core responsibilities. The product also provides a comfortable and intuitive UI with a wide range of useful security features.
What is most valuable?
Anti-DDoS protection is one of the most valuable features for us, particularly because availability is critical for our organization. At the same time, the overall WAF functionality is equally important, as it provides an additional layer of protection against web-based attacks and helps us secure our applications more comprehensively.
What needs improvement?
The main area for improvement is the flexibility of the security rule engine. Compared with some other vendors, there are fewer available conditions and limited support for complex rule logic. For example, there is no Destination Port condition, port-based restrictions cannot be expressed through URI matching, and the UI does not appear to support nested logical expressions beyond ALL and ANY. More granular conditions and support for nested AND/OR logic would make the solution significantly more flexible for advanced security policies. The limitation is the inability to construct something like: (A AND B) OR (C AND D) / A AND (B OR C).
For how long have I used the solution?
We have used the solution for one year.
Which solution did I use previously and why did I switch?
We previously used another security solution. We decided to move away from it because it did not meet our expectations, particularly regarding its cloud-based capabilities. We are more satisfied with Radware Cloud WAF and would recommend it over the previous solution, especially for cloud-based web application protection.
What's my experience with pricing, setup cost, and licensing?
There are no comments.
Which other solutions did I evaluate?
We considered other solutions such as Barracuda, Imperva, and Cloudflare.
What other advice do I have?
NA
reviewer2889597
Unified dashboard has simplified security operations and reduces false positives with AI models
Reviewed on Aug 21, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for Radware Cloud WAF Service is that I can say the overall experience provides application security for integrating web protections, port management, and mitigations. The platform offers many services. The AI-driven security model helps reduce false positives and improve capability. I can give you a quick, specific example of how I use Radware Cloud WAF Service for port management or with the AI security model.
How has it helped my organization?
Radware Cloud WAF Service has positively impacted my organization because it has a single integrated web dashboard and a unified cloud service. It has helped me manage all services in a single system.
A specific way this has improved my day-to-day work and my organization's operations is that the biggest advantage is having a single system.
What is most valuable?
The best features Radware Cloud WAF Service offers are that the platform integrates application DDoS protections into a single unified dashboard, which is much better for me.
This unified approach helps by providing a single pane of glass and operational advantage. Radware Cloud WAF Service provides 24/7 managed service that includes threat response, support, and AI-driven security features consisting of both positive and negative security models, which has really helped me.
I think the accuracy and reliability of the output from Radware Cloud WAF Service's AI capabilities are a positive security baseline. They can use the AI model so that capabilities can be improved and block zero-day exploits while reducing false positives, and also can provide API protection to stop multi-vector attacks with the help of AI.
Radware Cloud WAF Service has helped reduce my false positives through context awareness by looking at the entire request, not just a single keyword or pattern that might trigger an old rule, reducing noise and cloud scales. It also uses machine learning to analyze normal user behavior and separate valid requests from attacks, which is why it can be helpful for this cause. This may also be with the help of global threat intelligence.
What needs improvement?
Radware Cloud WAF Service can be improved in security features, as they can mitigate DDoS attacks and security threats.
On a scale of one to ten, I rate Radware Cloud WAF Service an eight out of ten because I think there are some security threats and dashboard reporting features which can be advanced with better dashboarding.
They can improve the scalability of Radware Cloud WAF Service.
For how long have I used the solution?
We have been using Radware Cloud WAF Service for two years.
What do I think about the stability of the solution?
Radware Cloud WAF Service is stable.
How are customer service and support?
The customer support is good compared to other web services from other vendors, and our TAC team provides remote support and resolves my queries on time and within SLA.
Which solution did I use previously and why did I switch?
We were previously using other services before Radware Cloud WAF Service because we have a better relationship with Radware, so currently we are using Radware Cloud WAF Service.
What other advice do I have?
I rate the customer support nine out of ten.
I will give advice to others looking into using Radware Cloud WAF Service that support is essential. If we are using any services, support is required from the vendor. I want to suggest that support, scalability, services, dashboard, and user interface are all good.
I use the API Discovery feature. The API Discovery feature is easy to use as I thought the physical form of the software features into API protection generally offers several security benefits for operational challenges and the engineering team, such as visibility, traffic controls, and data guards. Common challenges can be observed during my team's work when it comes to API, including partial alarm setup efforts and speed impact.
The use of CDN services offered by Radware in conjunction with Radware Cloud WAF Service is easy, as we can use the CDN for fully managed setup, single configuration portal, SSL management, and transport client-side tracking with the help of CDN services.
I assess Radware Cloud WAF Service for integrating with other systems and applications in my environment using the web page. I assess Radware Cloud WAF Service's ability to protect against zero-day attacks as effective because Radware Cloud Web Services mitigates zero-day attacks by combining automated quality security models with AI and analysis and virtual patching.
I assess Radware Cloud WAF Service for blocking unknown threats and attacks as effective because it handles unknown threats and attacks such as zero-day exploits through global threat intelligence and machine learning anomaly detection. My overall rating for this review is eight out of ten.
Yonaiker b.
Strong Threat Intelligence Feeds, but Load Balancing Needs More Configuration
Reviewed on Aug 13, 2026
Review provided by G2
What do you like best about the product?
Threat intelligence and attackers feed
What do you dislike about the product?
Load balance feature y not much configurable
What problems is the product solving and how is that benefiting you?