Check Point WAF as a Service (Premium, PAYG, Free 7 Days or 1M Requests) logo

    Check Point WAF as a Service (Premium, PAYG, Free 7 Days or 1M Requests)

    Check Point WAF as a Service (WAFaaS) is an AI-based web application, generative and agentic AI, and API security solution, delivering the highest protection against known and zero-day threats using advanced AI and IPS. WAFaaS provides multiple layers of protection: rate limiting, AI engines, IPS signatures, zero-day file security, bot protection, and comprehensive API discovery and schema validation. WAFaaS delivers a non-agent WAF, deployable within minutes, and adds advanced DDoS mitigation. Traffic is seamlessly routed through Check Point servers, which automatically issue SSL certificates.

    Ratings and reviews

    4.4
    139 ratings
    2 star
    1 star
    59%
    39%
    2%
    0%
    0%
    14 AWS reviews
    |
    125 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (139)
    Babu K

    Application security has reduced incidents and now needs UI fixes and shared exception rules

    Reviewed on Jul 22, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We have implemented Check Point WAF (formerly CloudGuard WAF) in our environment. We have been dealing with Check Point WAF (formerly CloudGuard WAF) for three months. We are using Check Point WAF (formerly CloudGuard WAF) for our company only.

    Currently, we are handling only the L7 part with Check Point WAF (formerly CloudGuard WAF), and we are planning to expand to the APIs and rate-limiting capabilities. We are not handling the network part, as we are only taking care of the security part with Check Point WAF (formerly CloudGuard WAF).

    We have a team of 15 people who handle Check Point WAF (formerly CloudGuard WAF) and other security aspects. We have only two administrators dedicated to Check Point WAF (formerly CloudGuard WAF).

    What is most valuable?

    We have seen measurable business and security outcomes since implementation. We have observed reduced incidents with Check Point WAF (formerly CloudGuard WAF).

    Check Point WAF (formerly CloudGuard WAF) has helped us reduce our false positives rate. Compared to other WAF solutions, Check Point WAF (formerly CloudGuard WAF) is user-friendly and very visible. When we review incidents with Check Point WAF (formerly CloudGuard WAF), it is clearly visible where the block occurred and it shows us detailed overview of the incident. In other products, I am not able to get the exact reason for the block, so I can identify where the block happened, and it is very user-friendly for me to add the policy or explicit policy there.

    What needs improvement?

    I face issues with the UI part of Check Point WAF (formerly CloudGuard WAF), as it malfunctions sometimes. Sometimes I do not see the icons in Check Point WAF (formerly CloudGuard WAF), and whenever I refresh the page, the icons remain invisible.

    Additional features I have considered with Check Point WAF (formerly CloudGuard WAF) include the ability to add an exception rule. Since we have multiple projects, I want to add an exception rule to all projects as a shared exception, but when adding it, I am unable to add it individually.

    For how long have I used the solution?

    I have been working in this field for three years.

    How are customer service and support?

    When I raise any TAC ticket for Check Point WAF (formerly CloudGuard WAF), I am satisfied with their points and their support, as I am receiving immediate responses from the TAC. I can easily rate their support for Check Point WAF (formerly CloudGuard WAF) an eight out of ten.

    An incident occurred regarding the Global Accelerator movement from CloudFront to Global Accelerator, and for that, it took one week to respond, which was delayed by five days.

    Which solution did I use previously and why did I switch?

    We considered the F5 WAF, Edge, and Radware before finally choosing Check Point WAF (formerly CloudGuard WAF).

    How was the initial setup?

    Compared to others, it was very easy for us to onboard Check Point WAF (formerly CloudGuard WAF) application.

    What about the implementation team?

    We received nice support from the OEM for Check Point WAF (formerly CloudGuard WAF), so they guided us, and we completed it within a week, onboarding one full project.

    What other advice do I have?

    The main reason why I chose Check Point WAF (formerly CloudGuard WAF) is about the cost, and we have a Check Point firewall and we also use endpoint security and email security, so we wanted to choose this as a one-stop solution.

    I do not have an idea regarding Check Point WAF (formerly CloudGuard WAF)'s ability for preemptively blocking zero-day attacks and detecting hidden anomalies, as it has been only three months, so we are yet to explore things in Check Point WAF (formerly CloudGuard WAF). Currently, we did not check the AI-driven threat detection and prevention capabilities in Check Point WAF (formerly CloudGuard WAF). Are you referring to the Gen AI or the built-in part of the WAF?

    Regarding the built-in AI-driven threat detection and prevention capabilities, I do not see any false positive detection based on the AI part in Check Point WAF (formerly CloudGuard WAF), so everything we are receiving is accurate results only. Based on that learning part, when Check Point WAF (formerly CloudGuard WAF) is in learning mode, the learning part is very helpful for us to filter those things, so after moving it to blocking, we are not receiving any false positive alerts or incidents. If I want to add an exception in Check Point WAF (formerly CloudGuard WAF), I can either add it in the shared one or in a local one.

    I have given this review an overall rating of 7.5 out of 10.

    Ashith S.

    Strong Web Traffic Visibility, But a Steep Learning Curve

    Reviewed on Jul 17, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Check Point WAF is its clear visibility into web traffic and blocked requests. It makes it easy to identify suspicious activity and fine-tune security policies. Once configured, it provides reliable protection with minimal day-to-day effort.
    What do you dislike about the product?
    The biggest drawback is the learning curve, especially for first-time users. The interface can feel crowded, and fine-tuning policiesThe initial setup and policy tuning can be time-consuming, especially if you're new to WAFs. The interface isn't always intuitive, and some configuration options require extra effort to understand. takes time to avoid false positives. Some configuration tasks could also be more intuitive.
    What problems is the product solving and how is that benefiting you?
    Check Point WAF helps protect our web applications from common attacks while reducing the need for constant manual monitoring. It gives us better visibility into suspicious traffic, allowing us to respond faster and manage security more efficiently.
    Samiksha C.

    Complex Setup, but Strong Security Features

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    I feel Check Point WAF is very basic but it does its job well in protecting the organization. It definitely helps when an employee is clicking on a suspicious link, like, preventing phishing attacks. I appreciate that it logs everything so that the SOC team stays aware. The feature I love the most is the firewall policy management and log monitoring via the smart console. I regularly work on analyzing the logs to investigate issues and validate security alerts. I also use the threat prevention features like IPS and antivirus to understand patterns and tune rules.
    What do you dislike about the product?
    I feel the setup is very complex and quite lengthy. It also has a high cost, and the performance impact is a bit lagging. It increases latency, reduces throughput, and needs proper sizing and tuning. I request the Check Point team to hopefully make the process easier.
    What problems is the product solving and how is that benefiting you?
    I use Check Point WAF to protect my organization, detecting endpoint activities and preventing security breaches. It logs everything, keeping our SOC team aware of potential phishing threats and ensuring we don't visit suspicious links.
    UTSAV A.

    Intuitive and Secure Firewall Solution

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    I find Check Point WAF very easy to use. Even if someone is new to firewall stuff, they can handle it effectively with some guidance on using its GUI. The setup is also quite straightforward; you can set it up in five to ten minutes using the GUI interface, which is quite comfortable for first-timers.
    What do you dislike about the product?
    As of now, I've used many firewalls, and while Check Point WAF's interface is good, I feel it could be improved a little bit. Compared to Fortinet, their GUI interface is slightly better than Check Point's. That's pretty much the only thing I would say needs improvement, although Check Point does have very good features compared to Palo Alto and ForteGate.
    What problems is the product solving and how is that benefiting you?
    I use Check Point WAF to secure our environment from vulnerabilities, performing URL and application-level filtering effectively.
    Milan D.

    Solid WAF Protection With a Learning Curve

    Reviewed on Jul 14, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best is the contextual AI engine that detects threats without relying on constant signature updates. It dramatically cut down our false positives compared to our previous signature-based WAF, which means less time spent tuning rules and chasing noise. Deployment across our cloud environments was straightforward, and the automatic learning of application behavior means new apps get protected without a ton of manual configuration. The unified management through the Infinity portal is also a big plus for us since we can see everything in one place.
    What do you dislike about the product?
    The initial setup and configuration felt more complex than expected, and the learning curve for tuning rules to reduce false positives was steep. Documentation could be more thorough in places, and support response times occasionally lagged when we ran into urgent issues. Pricing also feels on the higher side compared to some alternatives, especially as you scale traffic. Better dashboards and more intuitive policy management would go a long way
    What problems is the product solving and how is that benefiting you?
    We use Check Point WAF to protect our web applications and APIs from common threats like SQL injection, cross-site scripting, and bot traffic. Before adopting it, we struggled with manually managing security rules and staying ahead of emerging attacks. It's given us more consistent protection across our cloud environments and reduced the time our team spends triaging alerts. The automated threat detection lets us focus on other priorities while staying confident our applications are covered.
    Nekkala Nagendra

    Ai-driven cloud security has strengthened threat prevention and improved security posture

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security.

    I am looking for an AI-based solution that can strengthen my cloud-native security, automate security, and better prevent threats.

    I am looking for an AI-based solution and unified cloud-native security from the SaaS platform to improve my security posture.

    What is most valuable?

    Check Point WAF (formerly CloudGuard WAF) is a SaaS platform that gives unified cloud-native security across my applications, workloads, and network, allowing me to automate security, prevent threats, ensure compliance, and manage my security posture well across all my cloud environments.

    It conducts security scoring and risk scoring, which helps prioritize my security needs, and the advanced threat detection is also very fine, providing actionable information for my current security threats by collecting and analyzing data through threat actors and IOCs, offering tactical, technical, and operational features.

    What needs improvement?

    The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better.

    This all depends on how the rules are customized and configured, and it can also improve with planning during the initial configuration, including threat intelligence and APIs, so it could enhance how it defends against attacks and prompts injections.

    It can find the threat actors behind it, and I find that strategically and technically it is effective, although the AI-related features could improve, especially as global AI capabilities evolve, which are advancing more than what Check Point WAF (formerly CloudGuard WAF) provides compared to competitors.

    There are no glitches; I believe improvement could be made primarily in API Gateway and API security, especially by enabling enhanced AI-related features for better fine-tuning.

    For how long have I used the solution?

    I have experience of two years with the product.

    What do I think about the stability of the solution?

    It is stable.

    What do I think about the scalability of the solution?

    It is definitely a highly scalable solution without any doubt.

    How are customer service and support?

    The customer support is very good.

    Which solution did I use previously and why did I switch?

    Earlier, we had Microsoft Defender, which we replaced with Check Point WAF (formerly CloudGuard WAF), and we are now ensuring that policy enforcement and threat protection are better.

    How was the initial setup?

    The deployment and initial setup are really straightforward; they provide enough documentation, videos, and deployment documents that are really helpful to complete it faster.

    What was our ROI?

    The return on investment is very good as it has increased my security posture and the operational efficiency of my engineers.

    What's my experience with pricing, setup cost, and licensing?

    It is a little bit expensive, but the pricing model is acceptable, though a reduction would make it more competitive with leaders such as Palo Alto.

    Which other solutions did I evaluate?

    I purchased from a different source.

    What other advice do I have?

    The configurations are pretty easy, and it is plug-and-play, which gives me regular updates.

    I would assess the solution as positive in this regard.

    All the integrations are pretty easy through API connectivity, which I can recommend more, and it also helps with modern AI-based vulnerabilities to conduct token tests and improve detection.

    I would rate this review a 9 out of 10.

    Ejaz Ahmad

    AI-driven protection has strengthened our API security and reduced successful web attacks

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I am using Check Point WAF (formerly CloudGuard WAF). I am also using multiple FortiGate products. I am using the product for URL filtering, security, WAF, and VRF. Check Point WAF improves our ability to discover, monitor, and protect APIs.

    What is most valuable?

    I appreciate that Check Point WAF (formerly CloudGuard WAF) is an enterprise-grade service and a very good product that we have used. It offers smart AI protection as well. Since implementing Check Point WAF (formerly CloudGuard WAF), I have seen measurable outcomes; it has mostly stopped attacks through bots and API integrations. I see Check Point WAF (formerly CloudGuard WAF) as a good product in blocking zero-day attacks and detecting anomalies. It helps us a lot because the AI engines evaluate behavior on a real-time basis, and it can detect threats without signatures based on historical data.

    I believe AI-driven threat detection and prevention capabilities help in identifying, blocking, and responding to application threats more effectively. The AI helps in Check Point WAF (formerly CloudGuard WAF) because it creates a targeted exclusion list based on its learning period. It can detect and stop or prevent threats based on context tuning and historical data.

    What needs improvement?

    For Check Point WAF (formerly CloudGuard WAF), the negative aspects include the very high price, complex licensing, and the need for specialized trained people to configure it, which is comparatively more complicated than other firewalls like Palo Alto and FortiGate. The two areas for improvement are the price and the complexity of configuration.

    For how long have I used the solution?

    I started using Check Point WAF (formerly CloudGuard WAF) approximately four to five years ago.

    What do I think about the stability of the solution?

    I would give a score of nine for the stability of Check Point WAF (formerly CloudGuard WAF).

    What do I think about the scalability of the solution?

    I perceive scalability as limited due to challenges faced during DNS migration and HA mode.

    How are customer service and support?

    I find Check Point WAF (formerly CloudGuard WAF) support helpful, but it is not proficient. It is often reliant on the site engineer's involvement, and it does not match the support offered by leaders like Fortinet, who deploy their own trained personnel ready to help anytime.

    How was the initial setup?

    I find installation challenging, complex, and not easy, as it requires skilled professionals to configure the rules and threats, including AI configurations. The biggest challenge when deploying it is its architectural constraints, including limited synchronization during configuration, and there are many challenges involved in integration.

    What other advice do I have?

    I am mostly using firewall solutions. I am using a firewall with IT, OT, and enterprise-grade services. We deal with Check Point WAF (formerly CloudGuard WAF) products. I am speaking about Check Point WAF (formerly CloudGuard WAF), Web Application Firewall. We are just a user of Check Point WAF (formerly CloudGuard WAF). A context-based tooling helps more here because while the AI capabilities are learning, they could reduce the false positive rate. I have not integrated Check Point WAF (formerly CloudGuard WAF) with any other products.

    Despite the complex nature and high price, I think the product is worth buying because it is effective. The configuration is complex, so it is not as easy as with other products. However, I believe it is worth the investment because the security is excellent. For security, Check Point WAF (formerly CloudGuard WAF) is a leader without a doubt. Check Point WAF (formerly CloudGuard WAF) is a very good, highly secure enterprise-level product, but it does have limitations, including the price and the need for trained personnel. I also encounter many errors during HA mode configuration, which can be tricky. I have a hybrid model for deployment. I would rate this review an eight overall.

    Ayodeji A.

    Strong, Easy-to-Manage Web App Protection with Smart Automation

    Reviewed on Jul 07, 2026
    Review provided by G2
    What do you like best about the product?
    I like Check Point WAF because it provides strong protection against web application attacks while being easy to deploy and manage. Its automated policy generation, AI-driven threat detection, and low false positive rate reduce administrative effort without compromising security. I also appreciate its support for cloud environments, API protection, and centralised management, making it a reliable solution for securing modern web applications.
    What do you dislike about the product?
    One area that could be improved is making the platform even more intuitive for new users, especially when configuring advanced security policies. However, the available documentation and automation features help reduce the learning curve, and overall the solution provides strong security capabilities and flexibility.
    What problems is the product solving and how is that benefiting you?
    Check Point WAF helps me solve the challenge of protecting web applications from security threats while reducing the effort required to monitor and manage protection rules. I benefit from its automated threat detection, clear visibility into traffic, and ability to identify and block malicious activity. It gives me greater confidence that applications are better protected while making security management more efficient.
    Ijlal K.

    Good protection and easy to manage web security

    Reviewed on Jun 30, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Check Point WAF is easy to use and gives good protection without needing too much manual work all the time. It helps to block common web attacks and gives clear visibility about what is happening. The managed rules are also useful, and it is good that we can still adjust things when needed.
    What do you dislike about the product?
    One thing I dislike is that sometimes the setup and tuning can feel a bit complicated, especially in the start. Some alerts or rules need extra checking to avoid false positives, and it can take time to understand why something was blocked. The interface is good overall, but few parts could be more simple and easier to follow.
    What problems is the product solving and how is that benefiting you?
    Check Point WAF is solving the problem of protecting web applications from common attacks like bad bots, injection attempts and other unwanted traffic. It helps to block many threats before they reach the application, so we dont have to check everything manually. It also gives better visibility about what kind of requests are coming and what was blocked. The benefit is that security becomes more easy to manage and it saves time for the team.
    Hazem H.

    Strong Protection with Room for Onboarding Improvement

    Reviewed on Jun 20, 2026
    Review provided by G2
    What do you like best about the product?
    I use Check Point WAF to protect web applications and APIs from a wide range of cyber threats like SQL injection and cross-site scripting (XSS). What I like most about Check Point WAF is its ability to provide strong, automated protection for web applications while remaining easy to manage on a day-to-day basis. The platform effectively detects and blocks traffic. The initial setup of Check Point WAF was relatively straightforward, especially with the available documentation and guided configuration options. It provides strong protection against modern web application threats and offers good visibility through a centralized management interface.
    What do you dislike about the product?
    One challenge is the initial onboarding and policy tuning process. For organizations with complex or highly customized web applications, achieving the right balance between strong protection and minimizing false positives can require additional time and expertise.
    What problems is the product solving and how is that benefiting you?
    I use Check Point WAF to protect web applications and APIs from cyber threats like SQL injection and XSS. It offers strong, automated protection while being easy to manage daily. It effectively detects and blocks traffic, solving security challenges by defending against common and complex attacks.