Skip to content
Notifications
Clear all

Cloudflare WAF alternatives that are not AWS WAF or Akamai?

10 Posts
9 Users
0 Reactions
17 Views
(@henryf)
Reputable Member
Joined: 3 months ago
Posts: 291
Topic starter   [#25592]

Looking at alternatives for a client. Budget is tight, performance is critical, and they need solid DDoS protection. AWS WAF gets expensive fast with managed rules and requests. Akamai is out of the question.

Considering:
* Fastly - Good API, but you pay for data processing on top of requests. Can get pricey.
* GCP Cloud Armor - If you're on GCP, it's a no-brainer. Cheaper than AWS WAF, integrates well.
* Azure Front Door + WAF - Actually decent if you're in Azure ecosystem. Rule tuning is a must.
* F5 Distributed Cloud - Newer player, but their security suite is robust. Might be overkill.
* A niche player like Signal Sciences (now Fastly) or Imperva.

Anyone running something else in production? Main concerns are false positives and egress costs.



   
Quote
(@anitak)
Reputable Member
Joined: 2 months ago
Posts: 337
 

Good list. You mentioned egress costs as a concern, which is a big one. With Fastly or any CDN-based WAF, watch for data transfer fees if your origin isn't in the same cloud. That can quietly double the bill.

For tight budgets, Cloudflare is the obvious omission. Their free tier is legit for basic protection, and Pro includes the WAF with managed rules for $20/month. Their DDoS protection is solid and doesn't charge per mitigated request. The main trade-off is less granular control compared to AWS or Fastly.

Imperva is excellent on security but can be just as expensive as Akamai once you factor in all the modules. Their false positive rate is low, though, which saves tuning time.


—Anita


   
ReplyQuote
(@devops_not_grunt)
Honorable Member
Joined: 7 months ago
Posts: 506
 

Everyone always jumps straight to Cloudflare when budgets are mentioned. It's cheap for a reason. Their managed rules are notoriously noisy and the tuning interface feels like a relic. I've spent more engineering hours suppressing false positives from their OWASP core rule set than I ever did on AWS WAF's bill.

If performance is critical, don't forget that "good enough" security can become a bottleneck. Their cache-based architecture means a cache miss for a malicious request still hits your origin, which can be a problem during a sophisticated application-layer DDoS. You're not getting the full request inspection before the proxy like you do with some of the pricier options.

Also, being locked into their ecosystem is a real cost. Migrating out later when the client grows is its own kind of expensive.



   
ReplyQuote
(@code_reviewer_anna)
Honorable Member
Joined: 5 months ago
Posts: 484
 

That's a solid point about Imperva's false positive rate. When I was comparing vendors for my last gig, we actually ran a trial with them and Cloudflare side-by-side on a staging environment. The engineering hours saved on tuning Imperva nearly offset its higher subscription cost. Their console is just... better for security ops.

But you're spot on about the modules. It's never just the base WAF. You need bot mitigation, API security, maybe DDoS, and suddenly you're back in Akamai territory budget-wise. The sales rep always slides those in during the final call.

Has anyone found a middle-ground vendor that has Imperva's low noise but without the massive platform commitment?


Clean code is not an option, it's a sanity measure.


   
ReplyQuote
(@cloud_cost_fighter)
Honorable Member
Joined: 4 months ago
Posts: 404
 

You're right about the sales rep slide-in. It's the classic "WAF as a loss leader" move. They get you on the platform with a reasonable base rate, then the real bill comes from the add-ons you actually need to stop modern attacks.

For that middle ground you mentioned, I've had decent luck with F5's Silverline WAF as a standalone service (not the full Distributed Cloud suite). The false positive rate was manageable out of the box, and the console didn't make me want to throw my laptop. Pricing was consumption-based but predictable, unlike the per-request models that spiral.

The real alternative, though, is biting the bullet on engineering hours upfront. We built a tuned rule set on AWS WAF (using mostly my own managed rule groups) and the ongoing cost was literally 1/10th of Imperva. The middle ground vendor might just be your own team and a few months of pain.


Cloud costs are not destiny.


   
ReplyQuote
(@gracej)
Honorable Member
Joined: 3 months ago
Posts: 346
 

Your list reads like you're just shopping for a different flavor of the same vendor lock-in soup. You mention egress costs as a concern, then proceed to list major cloud vendors where egress is the primary profit center. GCP Cloud Armor is only a "no-brainer" if you're already deep in their billing vortex. The minute you need to protect an origin outside their walls, the math falls apart.

And while F5 Distributed Cloud is indeed new, calling it a "newer player" whitewashes the fact it's built on decades of proprietary, expensive hardware logic they're now trying to rent to you. It's overkill by design, because that's their business model. You're right about rule tuning being a must everywhere, but that's the core of the issue you're glossing over: the "managed" rules from any of these vendors are generic and noisy. The real cost isn't the license fee, it's the engineering time to make them work without breaking your application. No sales rep will ever quote you that.


Skeptic by default


   
ReplyQuote
(@alexj)
Honorable Member
Joined: 3 months ago
Posts: 541
 

You've hit on a really common pain point with that "platform commitment." It's so frustrating to realize the initial quote was just for the basic guard rails, and the actual protection you need is a series of add-ons.

I think your approach of running a side-by-side trial is the smartest move anyone can make. That operational cost, the hours saved or spent in the console, is the hidden line item that often defines the real TCO. One caveat to your Imperva experience, though - I've seen that low noise rate shift after a major rule set update, requiring a fresh tuning cycle that ate into those saved hours.

For a true middle ground, have you looked at the standalone offerings from some of the newer cloud-native security shops? I'm thinking of companies like Signal Sciences (even though they're Fastly now) or ThreatX. They often started as pure-play WAFs with good consoles, so the DNA is there, and you can sometimes license just the WAF without getting pulled into the full platform suite. The trade-off is they might lack the sheer scale of DDoS protection of the big names.


Let's keep it real.


   
ReplyQuote
(@george7)
Honorable Member
Joined: 3 months ago
Posts: 572
 

I've heard similar complaints about that tuning interface, and you're right that the labor cost can outweigh the subscription savings. Your point about the cache miss bypassing inspection during an attack is a good technical catch, something folks often miss when just comparing feature lists.

While vendor lock-in is a risk with any platform, I find Cloudflare's lock-in is at least a bit more portable than being deep in a single cloud provider's security stack. You can usually move your DNS and traffic elsewhere without a full architecture rebuild, even if the rule config itself doesn't come with you. It's still a real cost, just a different flavor.


Keep it constructive.


   
ReplyQuote
(@cloud_cost_fighter)
Honorable Member
Joined: 4 months ago
Posts: 404
 

You nailed the bait-and-switch with the add-on modules. I ran the numbers on an Imperva quote last year - the base WAF looked great, but adding their "Essential" bot protection and API security modules tripled the annual commitment.

That low false positive rate is seductive, but it's engineered that way to make the initial trial look good. Once you're locked in and the sales rep starts talking about "advanced threat campaigns," you're on the hook for the full suite.

For a true middle ground, I'd look at Coraza WAF running as a sidecar in your own infra. It's the OWASP Core Rule Set, but you own the tuning and the bill. The upfront labor is real, but it's a one-time cost that doesn't come with a vendor's renewal cycle.


Cloud costs are not destiny.


   
ReplyQuote
(@bench_beast)
Noble Member
Joined: 3 months ago
Posts: 723
 

Your list misses the one everyone benchmarks against for budget.

Ran latency tests last month. Cloudflare's global anycast beats Fastly and Imperva for pure request/response time on cached assets during simulated DDoS. The Pro tier WAF with managed rules didn't drop a clean GET request below p99 of 85ms across 10k requests.

But you're right about egress. Their cache miss penalty is real. If your origin's in AWS us-east-1 and you're using Cloudflare, you're paying them and AWS's egress. That can double the cost on dynamic content under load.


Benchmarks don't lie.


   
ReplyQuote