Listing Thumbnail

    Radware Cloud WAF

     Info
    Sold by: Radware 
    Deployed on AWS
    Radware Cloud WAF is a fully managed Cloud Application Protection Service providing the industry's most comprehensive web application security solution. It integrates Radware's cloud-delivered WAF technology, API protection, Bot management, application layer DDoS protection, client-side protection, analytics, threat detection and security feeds in a single portal.
    4.6

    Overview

    Radware Cloud WAF is a fully managed Cloud Application Protection Service providing the industry's most comprehensive web application security solution. The service integrates Radware's Cloud WAF, API Protection, Bot management, client-side and application layer DDoS protection in a single portal that provides security analytics, threat detection and real-time security feeds to protect applications against hacking, malicious bots, API exposure, Web DDoS attacks, supply chain attacks and other vulnerabilities. Radware's combination of negative and positive security models provides a complete level of protection against OWASP Top 10 threats and zero-day attacks. API Discovery and Protection - End-to-end API solution from Discovery to protection at a click of a button. Radware auto API discovery maps all of your applications documented and undocumented third-party APIs, automatically generates Open API schema files, generates tailored security policies to detect and block API-focused attacks in real time and enforce protection across all your APIs. Radware's advanced API protection eliminates your documenting and protecting APIs overheads and keeps your organization protected across the board. Bot Management - Integrated Bot Manager provides comprehensive mitigation options, such as Blockchain-based Crypto challenges to counter attacks. It ensures precise bot management for web, mobile, and API traffic by employing behavioral modeling, collective bot intelligence, and fingerprinting. This defense guards against all OWASP 21 automated threats, including account takeover, credential stuffing, DDoS, fraud, and web scraping, fortifying online operations. Web DDoS Protection - Industry leading application-layer L7 protection against DDoS attacks, based on Radware's unique machine-learning-based behavioral detection that distinguishes between legitimate and malicious traffic, and automatically generates granular signatures in real-time to protect against zero-day attacks. Best-in-class security against a wide variety of threats, including HTTP Floods, HTTP bombs, low-and-slow assaults, Brute Force attacks, and disruptive web DDoS Tsunamis. Client-side Protection - Easily block requests to suspicious third-party services in your supply chain and adhere to data security compliance standards. Protect against client-side attacks coming from third party JS services - Formjacking, Skimming,Magecart, automatically and continuously discover all third-party services in your supply chain with detailed activity tracking, as well as get alerts & threat level assessment according to multiple indicators, including script source and destination domain. Pricing We have 3 different pricing packages - Standard, Advanced and Complete. The Standard and Advanced packages come with some of the features while Complete provides full coverage.

    Highlights

    • Fully Managed Web Application Protection Service - 24x7 Fully managed security service by Radware's expert Emergency Response Team(ERT). Protect Against OWASP Vulnerabilities - Stay protected against 150+ known attack vectors, including the OWASP Top 10 Web Application Security Risks, Top 10 API Security Vulnerabilities, Top 21 Automated Threats To Web Applications, and Top 10 Client-side vulnerabilities
    • Detect, Manage and Mitigate Bots - Detect and distinguish between good and bad bots to protect websites, mobile apps and APIs. Easily optimize and customize your bot management policies to provide a better user experience and drive more ROI from your application traffic. End-to-end API Protection - From discovery to enforcement at a click of a button, Radware combines behavioral analysis and policy automation to protect from increasingly sophisticated API assaults.
    • Mitigate Application-Level DDoS Assaults - Radware's DDoS protection technologies provide the shortest time to detection and mitigation of most advanced and high volume HTTP-based DDoS assaults by utilizing patented behavioral analysis, machine learning-based engines. Protect Client-Side From Supply Chain Attacks - This solution offers advanced client side protection that ensures the protection of end users data when interacting with any third-party services in the application supply chain.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Radware Cloud WAF

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (24)

     Info
    Dimension
    Description
    Cost/Mbps
    Cloud Application Protection Standard,10 Mbps,1 Application - Monthly
    Cloud Application Protection Standard,10 Mbps,1 Application - Monthly
    $638.00
    Cloud Application Protection Standard,50 Mbps,1 Application - Monthly
    Cloud Application Protection Standard,50 Mbps,1 Application - Monthly
    $1,940.00
    Cloud Application Protection Standard,100 Mbps,1 Application - Monthly
    Cloud Application Protection Standard,100 Mbps,1 Application - Monthly
    $3,069.00
    Advanced_10
    Cloud Application Protection Advanced,10 Mbps,1 Application - Monthly
    $1,276.00
    Advanced_Addon
    Cloud Application Protection Advanced,1 Application Add-On - Monthly
    $127.00
    Complete_10
    Cloud Application Protection Complete,10 Mbps,1 Application - Montly
    $2,233.00
    Complete_Addon
    Cloud Application Protection Complete,1 Application Add-On - Monthly
    $193.00
    CDN_Add_on
    Cloud Application Protection CDN Service Enablement - Monthly
    $287.00
    CDDOS_OnDemand
    On-Demand Cloud DDoS Protection Service - Legitimate 10Mbps - Monthly
    $2,750.00
    CDDOS_AlwaysOn
    Always-On Cloud DDoS Protection Service - Legitimate 10Mbps - Monthly
    $4,950.00

    AI Insights

     Info

    Dimensions summary

    Pricing is usage-based and measured in Mbps of legitimate bandwidth. You start with a base Cloud Application Protection plan in three levels: Standard, Advanced, and Complete. Standard sizes by throughput (10, 50, or 100 Mbps) for one application. Advanced and Complete cover 10 Mbps for one application, with per-application add-ons to expand coverage. On top of any base plan, you can layer independent add-ons billed separately. These include CDN enablement, Cloud DDoS Protection (on-demand or always-on), Web DDoS, Firewall as a Service, Network Analytics, AI SOC Xpert, Access Logs, LLM Firewall, PCI DSS compliance, ERT Premium support, extra protected networks, and the SecurePath connector.

    Top-of-mind questions for buyers

    Pricing meters legitimate traffic bandwidth, measured in Mbps, not attack or blocked traffic. Your base plan is sized to a bandwidth tier, and many add-ons are also priced against legitimate bandwidth blocks, such as 10Mbps or 200Mbps units. Attack traffic that the service filters out does not count toward your metered bandwidth.
    You pick one base Cloud Application Protection plan, then layer optional add-ons that each bill separately. Charges add together, so your total is the base plan plus every add-on you select. Per-application add-ons extend coverage one application at a time. Bandwidth-based add-ons bill in fixed blocks, like 10Mbps or 200Mbps.
    Both meter legitimate bandwidth in 10Mbps units. On-Demand DDoS Protection engages only when mitigation is triggered, suited to occasional attack response. Always-On keeps protection active continuously, suited to constant exposure. You choose one model per subscription, and each is billed monthly against your legitimate bandwidth.
    www.radware.com
    Helpful?

    Vendor refund policy

    No refund offered

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Online Support Service Portal -Appropriate for non-critical issues, such as general inquiries, requests for technical documentation/ information, schedule support during an upcoming maintenance window, view installed base and manage support cases.24x7, where Internet service is available

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.6
    212 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    76%
    23%
    1%
    0%
    0%
    15 AWS reviews
    |
    197 external reviews
    External reviews are from G2  and PeerSpot .
    Bryan M.

    Excellent API protection and schema discovery, ideal for GraphQL

    Reviewed on Sep 08, 2026
    Review provided by G2
    What do you like best about the product?
    I like the protection it offers for APIs and API schema discovery, especially when creating GraphQL.
    What do you dislike about the product?
    When something new comes out, it takes a while to inform the public. It appears on the portal, and until one notices it says 'new', one needs to investigate on their own.
    What problems is the product solving and how is that benefiting you?
    The attacks targeted at the organization are now much better covered. With the AI module, the solution is further strengthened as it allows detecting potential AI-orchestrated attacks and offers protection for LLM models. Additionally, the reinforcement in API Protection is another plus that adds to the strength of cybersecurity.
    Moisés M.

    Excellent Web Security with an Intuitive, Clear Traffic Dashboard

    Reviewed on Sep 07, 2026
    Review provided by G2
    What do you like best about the product?
    Radware Cloud Application and API Protection provides excellent security for our web assets. The dashboard is intuitive, and it offers clear, easy-to-understand visibility into incoming traffic, which helps us monitor what’s happening at a glance.
    What do you dislike about the product?
    Tuning the system to minimize false positives requires continuous monitoring and manual adjustments, especially during the initial deployment phase or when launching new API endpoints.
    What problems is the product solving and how is that benefiting you?
    By using behavior-based intelligence to automate threat detection and policy updates, it helps our organization maintain continuous service uptime, reduce the need for manual security management, and keep performance smooth for legitimate users.
    Luis Alexander Velez B.

    Web protection has reduced municipal incidents and provides clear visibility into global attacks

    Reviewed on Sep 02, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Radware Cloud WAF Service is a tool for controlling the websites of the Municipio de Quito, and I have significant visibility with the tool.

    For example, on two principal sites of Quito, I have implemented geo-blocking policies, and I can detect attacks from China, Russia, and other locations. I have visibility for these attacks, and this is a fundamental tool to protect the municipality.

    How has it helped my organization?

    Radware Cloud WAF Service has positively impacted my organization by stopping attacks such as SQL injection attacks and geo-blocking attacks, which appear frequently in the tool logs.

    I have experienced a reduction of incidents in my organization since we started using it.

    What is most valuable?

    I use a WAF which stands out as one of the best features Radware Cloud WAF Service offers.

    It is focused on web services, and the API is a very recent proof of concept; I do not currently have features for web services. With Radware Cloud WAF Service, strong behavior, threat detection, and automated policy synchronization are features that could make it even better. I also observe DDoS protection and visibility of the forwarding and system logs.

    I assess Radware Cloud WAF Service for blocking unknown threats and attacks, primarily with threats such as geo-blocking and OWASP compliance, as well as SQL injection. I do not currently see other threats in the logs.

    What needs improvement?

    Radware Cloud WAF Service is easy to use, and configuring and monitoring the logs is straightforward.

    I do not currently have integration with a SIEM, but I have a SIEM integration planned for the next two months as I implement new tools to complete my cybersecurity area.

    To reduce false positives from geo-blocking, I maintain a list of public IPs. I currently experience many false positives with my front-end firewall, as I do not have a geo-blocking solution in this firewall, but I have reduced these false positive issues.

    For how long have I used the solution?

    I have been working in my current field for almost three years.

    What do I think about the stability of the solution?

    I do not have anything to add about my main use case or how I interact with Radware Cloud WAF Service. I have a proof of concept for APIs in Radware Cloud Services, but it is not yet complete.

    What do I think about the scalability of the solution?

    I am currently only integrating this and have no other implementation.

    How are customer service and support?

    I work with a partner; my company does not have a business relationship with this vendor other than being a customer.

    Which solution did I use previously and why did I switch?

    I do not have additional thoughts about Radware Cloud WAF Service.

    How was the initial setup?

    The integration is simple and easy with my sites.

    What about the implementation team?

    The purchase is not directly through a partner; I work with two partners, and they purchased and passed the licenses to the government entity.

    What was our ROI?

    It is easy for my team, and it has reduced incidents.

    What's my experience with pricing, setup cost, and licensing?

    I have a process to purchase additional features or services for Radware Cloud WAF Service.

    Which other solutions did I evaluate?

    I have the configuration for SIEM logs, and I need to complete the proof of concept of the API Discovery Automate.

    What other advice do I have?

    The advice I would give to others looking into using Radware Cloud WAF Service is that it is a tool for my business.

    Radware Cloud WAF Service remains a great solution that shines in high-security, high-throughput environments where behavioral detection and hybrid multi-cloud deployment flexibility are top priorities. My overall rating for this review is ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Gianluca T.

    Radware Cloud WAF

    Reviewed on Sep 02, 2026
    Review provided by G2
    What do you like best about the product?
    The completeness of the solution and features such as LLM Firewall, Bot Manager and completeness of the security events
    What do you dislike about the product?
    The integration with on-prem SIEM should be enhanced
    What problems is the product solving and how is that benefiting you?
    Protection web apps straight on the edge without worrying of upgrading the product every time
    reviewer2894466

    Web protections have prevented breaches and currently secure hundreds of critical applications

    Reviewed on Aug 31, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Radware Cloud WAF Service is protecting web application servers, as I am protecting 750 applications or more. Radware Cloud WAF Service protects the perimeter or the front end of the web applications, so I am using all the protections it comes with. I have nothing else to add about my main use case or how I am using Radware Cloud WAF Service.

    What is most valuable?

    The best features Radware Cloud WAF Service offers are the custom signatures and the API protection. The custom signatures and API protection have helped me because other vendors don't have API protection, so that's a significant advantage. Radware was chosen by Caterpillar because Radware is bleeding edge cybersecurity, though I was not at the company when these decisions were made.

    Radware Cloud WAF Service has positively impacted my organization by keeping us from having data breaches or denial of service attacks, which is the positive outcome of using the WAF. I don't really track the positive outcomes; management tracks more of the failures than the positives, and that's not my area, so I can't really comment.

    What needs improvement?

    I wish I had normalization because Radware Cloud WAF Service is not normalizing inputs properly and that's causing a lot of problems. Radware Cloud WAF Service can be improved as the unified portal is still buggy and mutual TLS needs to be enhanced because it only performs server side, and it needs to be client side. I've put in an NFR for that, so Radware knows about it.

    Regarding Radware Cloud WAF Service's AI capabilities, I think it needs more work as the AI makes a lot of mistakes. I've already commented on that; the governance and security is fine, but the accuracy is lacking. I assess Radware Cloud WAF Service for blocking unknown threats and attacks by saying it depends; if the signatures are up to date and its positive model is working properly, it's very good, but the problem is its normalization is broken, so Radware Cloud WAF Service can be bypassed quite a bit if you know what to look for, and this is a problem, which is why normalization needs to be fixed.

    I don't know if Radware Cloud WAF Service has helped reduce my false positives; I can't answer that as it seems to have more false positives than F5 from my experience. I assess Radware Cloud WAF Service's ability to protect against zero-day attacks by saying it depends on the zero-day attack; if it's a web DDoS, it protects fine, but if it's something else, how would I know, because the definition of a zero day is you don't have any protection for it.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for about two and a half years.

    What do I think about the stability of the solution?

    Radware Cloud WAF Service seems to be stable.

    What do I think about the scalability of the solution?

    The scalability of Radware Cloud WAF Service seems adequate.

    How are customer service and support?

    The customer support is not bad. I would rate the customer support an 8 on a scale of 1 to 10.

    How was the initial setup?

    I don't know how Radware Cloud WAF Service is deployed; I assume it's private cloud.

    What was our ROI?

    I haven't seen a return on investment from using Radware Cloud WAF Service, and I can share that Caterpillar is not that smart.

    What's my experience with pricing, setup cost, and licensing?

    I have no comment on my experience with pricing, setup cost, and licensing as I have nothing to do with any of that.

    Which other solutions did I evaluate?

    I cannot comment on whether I evaluated other options before choosing Radware Cloud WAF Service, as I was not here when those evaluations took place.

    What other advice do I have?

    I can't say whether there are any other improvements Radware Cloud WAF Service needs beyond what we've discussed. I assess Radware Cloud WAF Service for integrating with other systems and applications in my environment by saying it seems to integrate fine through the APIs, so it doesn't seem to be an issue there. I'm not using the API discovery feature at this time. I don't have any advice to give to others looking into using Radware Cloud WAF Service. I would rate this product an 8 overall.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews