Listing Thumbnail

    CloudGuard WAF-as-a-Service (Advanced, PAYG, Free 7 Days or 1M Requests)

     Info
    Deployed on AWS
    Check Point CloudGuard WAF-as-a-Service (WAFaaS) is an AI-based WAF solution delivering the highest protection against known and zero-day threats through advanced AI and IPS signatures. CloudGuard WAFaaS provides multiple layers of protection: rate limiting, AI engines, IPS signatures, zero-day file security, bot protection. CloudGuard WAFaaS delivers a non-agent WAF, deployable within minutes, and adds advanced DDoS mitigation. Traffic is seamlessly routed through Check Point servers, which automatically issue SSL certificates.

    Overview

    Play video

    Check Point CloudGuard WAF-as-a-Service (WAFaaS) is an automated solution that delivers superior benefits of a top-tier Web Application Firewall and API Protection, requiring minimal manual intervention. The AI engine continuously learns the behavior of your application, tracking changes throughout its lifecycle. This ensures a minimal false positive rate and reduces tedious rule tuning after each application change. CloudGuard WAFaaS delivers a non-agent WAF that can be deployed in less than 15 minutes. Traffic is effortlessly routed through Check Point servers, which automatically issue SSL certificates. Upon redirection, any HTTP requests are intercepted for inspection and forwarded to the application only after validating their security. CloudGuard WAFaaS is available in advanced and premium packages. Premium include API Discovery and Zero-day file security. The advanced package provides:

    • AI-based engines for prevention of Zero-day Attacks and OWASP Top 10 known attacks.
    • AI-based contextual analysis engine to ensure precise detection rate with minimal false positives.
    • Snort 3.0 signature enforcement engine.
    • Advanced DDoS mitigation to ensure your applications stay accessible to legitimate users by mitigating attacks that overwhelm your network, servers, or applications.
    • Rate limiting based on identifiers such as IP address and XFF - limited to 5 rules.
    • Intrusion Prevention (IPS), over 2,800 Web CVEs, based on award-winning NSS-Certified IPS.
    • Include 3 months of full logs retention - based on the fair usage policy.

    You are entitled to free usage of 7 days or 1M HTTP requests whatever comes first, after that you will be billed.

    Highlights

    • Zero-day prevention: CloudGuard WAFaaS has demonstrated prevention of zero-day exploits across a wide spectrum of security events, including log4shell, text4shell, and MOVEit, all in real-time.
    • Deployed within minutes, usage-based pricing: CloudGuard WAFaaS delivers a non-agent Web application Firewall, deployable within minutes. Requires one-time DNS configuration. The consumption is based on the actual number of requests processed by your applications.
    • Prevent DDoS and automated bot attacks: CloudGuard WAFaaS provides real-time detection and automatic mitigation protection against Distributed Denial of Service (DDoS) attacks and bot-driven assaults.

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CloudGuard WAF-as-a-Service (Advanced, PAYG, Free 7 Days or 1M Requests)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (4)

     Info
    Dimension
    Cost/unit
    First 10M HTTP requests
    $1,500.00
    10M-60M HTTP requests (price per 1M)
    $38.00
    60M-160M HTTP requests (price per 1M)
    $22.00
    160M HTTP requests and above (price per 1M)
    $15.00

    Vendor refund policy

    No Refunds.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    https://supportcenter.checkpoint.com/supportcenter/portal  24x7 email support with emergency phone number. Premier support available for enterprise customers.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.2
    7 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    14%
    71%
    14%
    0%
    0%
    7 AWS reviews
    |
    65 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Ruben Cordero

    AI-driven threat detection has reduced incidents and saved team hours weekly

    Reviewed on Nov 22, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Check Point CloudGuard WAF 's main use case is protecting web application APIs from external threats. It helps us block common attacks like SQL injections, cross-site scripting, and bot traffic, while also ensuring compliance with the security standards.

    One unique aspect of our use case for Check Point CloudGuard WAF  is how we leverage it to protect customer APIs that are critical to our business. Because we develop and host several in-house applications, we needed a solution that could adapt quickly to new endpoints and traffic patterns. Check Point CloudGuard WAF  has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning.

    What is most valuable?

    The best features Check Point CloudGuard WAF  offers include AI-driven threat prevention, protection against OWASP Top 10, and zero-day attacks.

    The zero-day attack protection in Check Point CloudGuard WAF has been very effective for us. Instead of waiting for signature updates or manual rule changes, the system uses AI to detect abnormal patterns and block suspicious traffic automatically.

    Check Point CloudGuard WAF has positively impacted our organization by strengthening application security while reducing the workload in our team. The AI-driven protection against zero-day attacks and OWASP Top 10 vulnerabilities means threats are blocked automatically before patches are applied. This noticeably reduced the number of incidents we needed to investigate, freeing up time for more strategic projects.

    Check Point CloudGuard WAF's ability to preemptively block zero-day attacks is one of its strongest advantages. Instead of relying on traditional signature updates, it uses AI and contextual analysis to spot abnormal traffic patterns and block them before they can exploit vulnerabilities. For example, during the Log4Shell disclosure, Check Point CloudGuard WAF was already blocking the suspicious payloads without us needing to manually adjust rules.

    The breach reduction feature of Check Point CloudGuard WAF is one of the most impactful aspects of the solution. It proactively blocks suspicious traffic before it can exploit vulnerabilities, which has noticeably reduced the risk of breach in our environment.

    What needs improvement?

    Check Point CloudGuard WAF's support is only available in English. I gave Check Point CloudGuard WAF a rating of 9 out of 10 because the language limitation of support keeps it from being a perfect score, as I prefer support in different languages.

    For how long have I used the solution?

    I have been using Check Point CloudGuard WAF for around six years.

    What do I think about the stability of the solution?

    Check Point CloudGuard WAF is very stable.

    What do I think about the scalability of the solution?

    Check Point CloudGuard WAF's scalability is very good, and I have no issues with this.

    How are customer service and support?

    Check Point CloudGuard WAF's customer support is very great and very fast.

    I would give Check Point CloudGuard WAF a rating of 10 for customer support.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I previously used Azure  WAF, but I decided to switch to Check Point CloudGuard WAF.

    How was the initial setup?

    The first deployment of Check Point CloudGuard WAF was initially difficult because the documentation is not intuitive, but it is no longer an issue.

    What about the implementation team?

    I do not utilize Check Point CloudGuard WAF alongside any other Check Point products. I prefer to use a centralized WAF or specialist WAF to assess the efficiency improvements provided by Check Point CloudGuard WAF compared to traditional WAFs.

    What was our ROI?

    I have saved a significant amount of time and resources since implementing Check Point CloudGuard WAF. Before, our teams often spent several hours manually tuning rules and chasing false positives. The detection has now cut the workload by more than half, freeing up three or four hours less per week.

    Check Point CloudGuard WAF has reduced our total cost of ownership by approximately 10%. I consider the time saved as a return on investment since using Check Point CloudGuard WAF.

    What's my experience with pricing, setup cost, and licensing?

    The pricing, setup cost, and licensing for Check Point CloudGuard WAF are excellent, and I have no concerns with them.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Check Point CloudGuard WAF.

    What other advice do I have?

    Check Point CloudGuard WAF is an excellent security tool, and my advice to others looking into using it is that it is complete and modern. Check Point CloudGuard WAF is an excellent solution for web applications, and you should consider it for future deployments. I would rate this product 9 out of 10.

    Alejandro M.

    Seamless Deployment and Robust Threat Protection with Minimal Maintenance

    Reviewed on Nov 19, 2025
    Review provided by G2
    What do you like best about the product?
    The combination of seamless deployment and strong, intelligent threat protection is the greatest upside. The Ease of Implementation was a significant win, allowing us to onboard critical applications with minimal downtime or configuration overhead. The managed intelligence behind the WAF dramatically reduces false positives while effectively stopping complex Layer 7 attacks, freeing up our team to focus on other priorities. Its low maintenance requirement and high-fidelity alerting are also major benefits.
    What do you dislike about the product?
    While the core WAF functionality is excellent, the reporting and dashboard visualization could be improved for enterprise-level visibility. It sometimes requires extra effort to correlate specific security events across a large fleet of applications outside of the primary console. Furthermore, the initial licensing model required a bit more negotiation to align perfectly with our specific scale-out architecture. However, the strong Customer Support helped us resolve these initial issues quickly.
    What problems is the product solving and how is that benefiting you?
    The primary problem solved is the comprehensive and proactive defense of critical web applications and APIs against the escalating threat landscape, particularly zero-day attacks and OWASP Top 10 vulnerabilities. This ensures regulatory compliance is consistently met without excessive manual oversight. The benefit is a significant reduction in operational risk and a dramatic increase in security team efficiency, as the intelligent, automated protection means we spend far less time on triage and fine-tuning rules, ultimately accelerating our application deployment timelines.
    Computer Software

    Seamless Cloud Integration and Effortless Deployment for DevOps

    Reviewed on Nov 19, 2025
    Review provided by G2
    What do you like best about the product?
    I liked that it integrates well with cloud environments and supports laC workflows and this makes the deployment smooth for the Devops team.It is very effective against common web attacks like SQL injection, XSS etc.
    What do you dislike about the product?
    The User Interface is powerful but it felt slightly overwhelming at first open. Some advanced and powerful options are bit hidden in the menus. Sometimes I felt UI lag issues.
    What problems is the product solving and how is that benefiting you?
    Cloudguard WAF helped us to tackle two major issues , securing our API's and protecting out web app from modern attacks pattern. During our trial we were able to quickly setup protections against SQL injection and DDOs attack. It gave us better visibility into the suspicious requests and helped us to understand where our product was vulnerable. We used the trial to evaluate whether we could adopt it long term and the experience was vey positive.
    Medical Devices

    My review: Check Point CloudGuard WAF

    Reviewed on Nov 18, 2025
    Review provided by G2
    What do you like best about the product?
    the level of automation! The fact that we didnt have to rely on constant signature updates and changes. The system, sensitive documentation and quality management system are fully protected.
    What do you dislike about the product?
    The learning curve! I always say it's totally worth it after you've crossed it. It may feel at times that more guidance is needed to really get acquainted with the workings od the tool.
    What problems is the product solving and how is that benefiting you?
    In the medical device industry and from my point of view, protecting sensitive patient files is the most important feature it has. It is also protecting product art, patents, schemes and product development information.
    aditya t.

    Powerful, Automated Protection for Modern Cloud Applications

    Reviewed on Nov 18, 2025
    Review provided by G2
    What do you like best about the product?
    It's designed to protect our websites , Api and cloud applications from cyber attacks. This protects our application from being hacked. random heavy traffic does not cause the website to go down. reduces false positives saving time for developers and testing. fully automated setup requires very little manual tuning. very powerful for modern cloud native applications.
    What do you dislike about the product?
    It's many users say that its policies and rules are not easy to configure correctly. it's very expensive. technical engineers are not always available and troubleshooting takes time.
    What problems is the product solving and how is that benefiting you?
    it's protects your website and API's from all types of cyberattacks , keep data secure makes compliance esay and strengthens your business continuity. cybercriminals try to steal personal , financial and sensitive data stored in databases . cloud guard blocks such attempts by using DPI.
    View all reviews