Check Point WAF (formerly CloudGuard WAF) logo

    Check Point WAF (formerly CloudGuard WAF)

    As your organization expands its web applications, generative AI tools, and APIs, the attack surface grows, increasing exposure to sophisticated cyber threats. Check Point WAF for AWS is a prevention-first, AI-powered web application firewall (WAF) solution designed to deliver robust web application, generative and agentic AI, and API security without compromising efficiency or ease of management.

    Ratings and reviews

    4.4
    138 ratings
    2 star
    1 star
    60%
    38%
    2%
    0%
    0%
    14 AWS reviews
    |
    124 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (138)
    Samiksha C.

    Complex Setup, but Strong Security Features

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    I feel Check Point WAF is very basic but it does its job well in protecting the organization. It definitely helps when an employee is clicking on a suspicious link, like, preventing phishing attacks. I appreciate that it logs everything so that the SOC team stays aware. The feature I love the most is the firewall policy management and log monitoring via the smart console. I regularly work on analyzing the logs to investigate issues and validate security alerts. I also use the threat prevention features like IPS and antivirus to understand patterns and tune rules.
    What do you dislike about the product?
    I feel the setup is very complex and quite lengthy. It also has a high cost, and the performance impact is a bit lagging. It increases latency, reduces throughput, and needs proper sizing and tuning. I request the Check Point team to hopefully make the process easier.
    What problems is the product solving and how is that benefiting you?
    I use Check Point WAF to protect my organization, detecting endpoint activities and preventing security breaches. It logs everything, keeping our SOC team aware of potential phishing threats and ensuring we don't visit suspicious links.
    UTSAV A.

    Intuitive and Secure Firewall Solution

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    I find Check Point WAF very easy to use. Even if someone is new to firewall stuff, they can handle it effectively with some guidance on using its GUI. The setup is also quite straightforward; you can set it up in five to ten minutes using the GUI interface, which is quite comfortable for first-timers.
    What do you dislike about the product?
    As of now, I've used many firewalls, and while Check Point WAF's interface is good, I feel it could be improved a little bit. Compared to Fortinet, their GUI interface is slightly better than Check Point's. That's pretty much the only thing I would say needs improvement, although Check Point does have very good features compared to Palo Alto and ForteGate.
    What problems is the product solving and how is that benefiting you?
    I use Check Point WAF to secure our environment from vulnerabilities, performing URL and application-level filtering effectively.
    Milan D.

    Solid WAF Protection With a Learning Curve

    Reviewed on Jul 14, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best is the contextual AI engine that detects threats without relying on constant signature updates. It dramatically cut down our false positives compared to our previous signature-based WAF, which means less time spent tuning rules and chasing noise. Deployment across our cloud environments was straightforward, and the automatic learning of application behavior means new apps get protected without a ton of manual configuration. The unified management through the Infinity portal is also a big plus for us since we can see everything in one place.
    What do you dislike about the product?
    The initial setup and configuration felt more complex than expected, and the learning curve for tuning rules to reduce false positives was steep. Documentation could be more thorough in places, and support response times occasionally lagged when we ran into urgent issues. Pricing also feels on the higher side compared to some alternatives, especially as you scale traffic. Better dashboards and more intuitive policy management would go a long way
    What problems is the product solving and how is that benefiting you?
    We use Check Point WAF to protect our web applications and APIs from common threats like SQL injection, cross-site scripting, and bot traffic. Before adopting it, we struggled with manually managing security rules and staying ahead of emerging attacks. It's given us more consistent protection across our cloud environments and reduced the time our team spends triaging alerts. The automated threat detection lets us focus on other priorities while staying confident our applications are covered.
    Nekkala Nagendra

    Ai-driven cloud security has strengthened threat prevention and improved security posture

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security.

    I am looking for an AI-based solution that can strengthen my cloud-native security, automate security, and better prevent threats.

    I am looking for an AI-based solution and unified cloud-native security from the SaaS platform to improve my security posture.

    What is most valuable?

    Check Point WAF (formerly CloudGuard WAF) is a SaaS platform that gives unified cloud-native security across my applications, workloads, and network, allowing me to automate security, prevent threats, ensure compliance, and manage my security posture well across all my cloud environments.

    It conducts security scoring and risk scoring, which helps prioritize my security needs, and the advanced threat detection is also very fine, providing actionable information for my current security threats by collecting and analyzing data through threat actors and IOCs, offering tactical, technical, and operational features.

    What needs improvement?

    The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better.

    This all depends on how the rules are customized and configured, and it can also improve with planning during the initial configuration, including threat intelligence and APIs, so it could enhance how it defends against attacks and prompts injections.

    It can find the threat actors behind it, and I find that strategically and technically it is effective, although the AI-related features could improve, especially as global AI capabilities evolve, which are advancing more than what Check Point WAF (formerly CloudGuard WAF) provides compared to competitors.

    There are no glitches; I believe improvement could be made primarily in API Gateway and API security, especially by enabling enhanced AI-related features for better fine-tuning.

    For how long have I used the solution?

    I have experience of two years with the product.

    What do I think about the stability of the solution?

    It is stable.

    What do I think about the scalability of the solution?

    It is definitely a highly scalable solution without any doubt.

    How are customer service and support?

    The customer support is very good.

    Which solution did I use previously and why did I switch?

    Earlier, we had Microsoft Defender, which we replaced with Check Point WAF (formerly CloudGuard WAF), and we are now ensuring that policy enforcement and threat protection are better.

    How was the initial setup?

    The deployment and initial setup are really straightforward; they provide enough documentation, videos, and deployment documents that are really helpful to complete it faster.

    What was our ROI?

    The return on investment is very good as it has increased my security posture and the operational efficiency of my engineers.

    What's my experience with pricing, setup cost, and licensing?

    It is a little bit expensive, but the pricing model is acceptable, though a reduction would make it more competitive with leaders such as Palo Alto.

    Which other solutions did I evaluate?

    I purchased from a different source.

    What other advice do I have?

    The configurations are pretty easy, and it is plug-and-play, which gives me regular updates.

    I would assess the solution as positive in this regard.

    All the integrations are pretty easy through API connectivity, which I can recommend more, and it also helps with modern AI-based vulnerabilities to conduct token tests and improve detection.

    I would rate this review a 9 out of 10.

    Ejaz Ahmad

    AI-driven protection has strengthened our API security and reduced successful web attacks

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I am using Check Point WAF (formerly CloudGuard WAF). I am also using multiple FortiGate products. I am using the product for URL filtering, security, WAF, and VRF. Check Point WAF improves our ability to discover, monitor, and protect APIs.

    What is most valuable?

    I appreciate that Check Point WAF (formerly CloudGuard WAF) is an enterprise-grade service and a very good product that we have used. It offers smart AI protection as well. Since implementing Check Point WAF (formerly CloudGuard WAF), I have seen measurable outcomes; it has mostly stopped attacks through bots and API integrations. I see Check Point WAF (formerly CloudGuard WAF) as a good product in blocking zero-day attacks and detecting anomalies. It helps us a lot because the AI engines evaluate behavior on a real-time basis, and it can detect threats without signatures based on historical data.

    I believe AI-driven threat detection and prevention capabilities help in identifying, blocking, and responding to application threats more effectively. The AI helps in Check Point WAF (formerly CloudGuard WAF) because it creates a targeted exclusion list based on its learning period. It can detect and stop or prevent threats based on context tuning and historical data.

    What needs improvement?

    For Check Point WAF (formerly CloudGuard WAF), the negative aspects include the very high price, complex licensing, and the need for specialized trained people to configure it, which is comparatively more complicated than other firewalls like Palo Alto and FortiGate. The two areas for improvement are the price and the complexity of configuration.

    For how long have I used the solution?

    I started using Check Point WAF (formerly CloudGuard WAF) approximately four to five years ago.

    What do I think about the stability of the solution?

    I would give a score of nine for the stability of Check Point WAF (formerly CloudGuard WAF).

    What do I think about the scalability of the solution?

    I perceive scalability as limited due to challenges faced during DNS migration and HA mode.

    How are customer service and support?

    I find Check Point WAF (formerly CloudGuard WAF) support helpful, but it is not proficient. It is often reliant on the site engineer's involvement, and it does not match the support offered by leaders like Fortinet, who deploy their own trained personnel ready to help anytime.

    How was the initial setup?

    I find installation challenging, complex, and not easy, as it requires skilled professionals to configure the rules and threats, including AI configurations. The biggest challenge when deploying it is its architectural constraints, including limited synchronization during configuration, and there are many challenges involved in integration.

    What other advice do I have?

    I am mostly using firewall solutions. I am using a firewall with IT, OT, and enterprise-grade services. We deal with Check Point WAF (formerly CloudGuard WAF) products. I am speaking about Check Point WAF (formerly CloudGuard WAF), Web Application Firewall. We are just a user of Check Point WAF (formerly CloudGuard WAF). A context-based tooling helps more here because while the AI capabilities are learning, they could reduce the false positive rate. I have not integrated Check Point WAF (formerly CloudGuard WAF) with any other products.

    Despite the complex nature and high price, I think the product is worth buying because it is effective. The configuration is complex, so it is not as easy as with other products. However, I believe it is worth the investment because the security is excellent. For security, Check Point WAF (formerly CloudGuard WAF) is a leader without a doubt. Check Point WAF (formerly CloudGuard WAF) is a very good, highly secure enterprise-level product, but it does have limitations, including the price and the need for trained personnel. I also encounter many errors during HA mode configuration, which can be tricky. I have a hybrid model for deployment. I would rate this review an eight overall.

    Ayodeji A.

    Strong, Easy-to-Manage Web App Protection with Smart Automation

    Reviewed on Jul 07, 2026
    Review provided by G2
    What do you like best about the product?
    I like Check Point WAF because it provides strong protection against web application attacks while being easy to deploy and manage. Its automated policy generation, AI-driven threat detection, and low false positive rate reduce administrative effort without compromising security. I also appreciate its support for cloud environments, API protection, and centralised management, making it a reliable solution for securing modern web applications.
    What do you dislike about the product?
    One area that could be improved is making the platform even more intuitive for new users, especially when configuring advanced security policies. However, the available documentation and automation features help reduce the learning curve, and overall the solution provides strong security capabilities and flexibility.
    What problems is the product solving and how is that benefiting you?
    Check Point WAF helps me solve the challenge of protecting web applications from security threats while reducing the effort required to monitor and manage protection rules. I benefit from its automated threat detection, clear visibility into traffic, and ability to identify and block malicious activity. It gives me greater confidence that applications are better protected while making security management more efficient.
    Ijlal K.

    Good protection and easy to manage web security

    Reviewed on Jun 30, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Check Point WAF is easy to use and gives good protection without needing too much manual work all the time. It helps to block common web attacks and gives clear visibility about what is happening. The managed rules are also useful, and it is good that we can still adjust things when needed.
    What do you dislike about the product?
    One thing I dislike is that sometimes the setup and tuning can feel a bit complicated, especially in the start. Some alerts or rules need extra checking to avoid false positives, and it can take time to understand why something was blocked. The interface is good overall, but few parts could be more simple and easier to follow.
    What problems is the product solving and how is that benefiting you?
    Check Point WAF is solving the problem of protecting web applications from common attacks like bad bots, injection attempts and other unwanted traffic. It helps to block many threats before they reach the application, so we dont have to check everything manually. It also gives better visibility about what kind of requests are coming and what was blocked. The benefit is that security becomes more easy to manage and it saves time for the team.
    Hazem H.

    Strong Protection with Room for Onboarding Improvement

    Reviewed on Jun 20, 2026
    Review provided by G2
    What do you like best about the product?
    I use Check Point WAF to protect web applications and APIs from a wide range of cyber threats like SQL injection and cross-site scripting (XSS). What I like most about Check Point WAF is its ability to provide strong, automated protection for web applications while remaining easy to manage on a day-to-day basis. The platform effectively detects and blocks traffic. The initial setup of Check Point WAF was relatively straightforward, especially with the available documentation and guided configuration options. It provides strong protection against modern web application threats and offers good visibility through a centralized management interface.
    What do you dislike about the product?
    One challenge is the initial onboarding and policy tuning process. For organizations with complex or highly customized web applications, achieving the right balance between strong protection and minimizing false positives can require additional time and expertise.
    What problems is the product solving and how is that benefiting you?
    I use Check Point WAF to protect web applications and APIs from cyber threats like SQL injection and XSS. It offers strong, automated protection while being easy to manage daily. It effectively detects and blocks traffic, solving security challenges by defending against common and complex attacks.
    SreejeshSoman

    Cloud-native protection has secured our web workloads and simplifies autonomous threat defense

    Reviewed on Jun 19, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I typically use Check Point WAF (formerly CloudGuard WAF) for protecting cloud workspaces, which includes cloud applications and websites hosted on cloud platforms, especially Amazon or Azure. My customers are using Check Point WAF (formerly CloudGuard WAF) as a standalone product in the cloud, not in conjunction with any other Check Point products.

    What is most valuable?

    Check Point WAF (formerly CloudGuard WAF) is especially valuable because of its cloud-native architecture and AI autonomous protection capabilities. It does not require extensive administrative skills or experience to operate. Within minutes of redirection, the platform can be up and running, which is one of the key benefits of Check Point WAF (formerly CloudGuard WAF).

    Traditional WAF solutions require rule tuning with manual updates, but Check Point WAF (formerly CloudGuard WAF) includes a self-learning tool that suggests changes automatically. This significantly reduces the need for manual interruption and administrative effort.

    Stability is one of the unique features of Check Point WAF (formerly CloudGuard WAF). I do not have any concerns regarding hardware or security stability, with a reliability rating of 99.9%.

    What needs improvement?

    Check Point WAF (formerly CloudGuard WAF) needs to offer more competitive pricing. There are many other cloud WAF products available, and when comparing costs, other vendors have a significant cost advantage.

    Check Point WAF (formerly CloudGuard WAF) pricing is not as competitive as other original equipment manufacturers like Cloudflare or Array WAF. I feel the pricing is on the higher side compared to these alternatives.

    Application Delivery Controller (ADC) features are limited in Check Point WAF (formerly CloudGuard WAF). While we can integrate with ADC, not all inputs from the forest can be uploaded to Check Point WAF (formerly CloudGuard WAF), which is a practical issue we have encountered in customer use cases.

    For how long have I used the solution?

    I have been using this solution for approximately one and a half years.

    What do I think about the stability of the solution?

    Stability is one of the unique features of Check Point WAF (formerly CloudGuard WAF). I do not have any concerns regarding hardware or security stability.

    What do I think about the scalability of the solution?

    On a cloud platform, I do not foresee any scalability limitations. Check Point WAF (formerly CloudGuard WAF) has explicitly expandable features, so I do not forecast any constraints.

    How are customer service and support?

    I am satisfied with Check Point WAF (formerly CloudGuard WAF) customer support. They have a dedicated Tactics and Operations Center (TAC) team with service level agreements in place. We typically receive business hours or 24/7 support depending on our license level.

    Which solution did I use previously and why did I switch?

    I have not deployed Check Point WAF (formerly CloudGuard WAF) on-premises because their capital expenditure cost is significantly higher than other brands. I have not had the opportunity to deploy an on-premises solution from Check Point.

    How was the initial setup?

    The biggest advantage of Check Point WAF (formerly CloudGuard WAF) is that it is a cloud-native platform. Check Point WAF (formerly CloudGuard WAF) is competitive with other original equipment manufacturers. I am not mentioning low-range products, but when compared with offerings from Cloudflare or Array WAF, I feel Check Point WAF (formerly CloudGuard WAF) pricing is on the higher side.

    What about the implementation team?

    Application Delivery Controller (ADC) features are limited in Check Point WAF (formerly CloudGuard WAF). We can integrate with ADC, but not all inputs from the forest can be uploaded to Check Point WAF (formerly CloudGuard WAF). This is a practical issue we have encountered in customer use cases.

    What was our ROI?

    From my experience and client experience, Check Point WAF (formerly CloudGuard WAF) is a good product for cost of ownership and return on investment.

    Check Point WAF (formerly CloudGuard WAF) offers a subscription-based, pay-as-you-use model with monthly or yearly subscription options. This subscription model helps customers manage their costs as an operational expenditure rather than a capital expenditure.

    What's my experience with pricing, setup cost, and licensing?

    All original equipment manufacturers mention zero-day attacks and the exploitation of previously unknown vulnerabilities, and Check Point WAF (formerly CloudGuard WAF) also includes this feature. As a tool, it is good, but I did not observe any extraordinary service from Check Point WAF (formerly CloudGuard WAF) regarding zero-day attack protection. It is a good feature, but I did not find particularly unique characteristics.

    Which other solutions did I evaluate?

    Application Delivery Controller (ADC) features are limited in Check Point WAF (formerly CloudGuard WAF). We can integrate with ADC, but not all inputs from the forest can be uploaded to Check Point WAF (formerly CloudGuard WAF). This is a practical issue we have encountered in customer use cases.

    Check Point WAF (formerly CloudGuard WAF) does have higher ratings in some areas.

    What other advice do I have?

    Check Point WAF (formerly CloudGuard WAF) is a good product for total cost of ownership and return on investment. From my experience and client experience, Check Point WAF (formerly CloudGuard WAF) offers a subscription-based, pay-as-you-use model with monthly or yearly subscription options. This subscription model helps customers manage their costs as an operational expenditure rather than a capital expenditure. I would rate this product overall as a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Dominika T.

    Low False Positives and an Easy Setup from Day One

    Reviewed on Jun 17, 2026
    Review provided by G2
    What do you like best about the product?
    I like the most that since beginning of set up the rate of False Positives is significantly lower then in other tools. Also 0 day protection is working well and does not require manual rules updates.
    What do you dislike about the product?
    There is not enough of technical documentation and also initial set up is complicated. Will be easier if will be more knowledge-base articles available.
    What problems is the product solving and how is that benefiting you?
    It protect assets in hybrid, cloud and on-premises environments. Allows for Iac for better configuration so it allows to save some time of cloud security engineers.