Skip to content
Notifications
Clear all

Migrated from Cloudflare to Azure WAF - any regrets?

2 Posts
2 Users
0 Reactions
1 Views
(@devops_rookie_22)
Reputable Member
Joined: 4 months ago
Posts: 157
Topic starter   [#5242]

Hey everyone, I'm pretty new to this whole cloud/WAF space. I've been learning a lot about Docker and K8s, but infrastructure security is still a bit over my head.

My team recently moved our web apps from Cloudflare's WAF/DDoS to Azure WAF. The main reason was to keep everything within our Azure subscription for simplicity. I'm just curious, has anyone else made this switch? Do you miss anything from Cloudflare, especially for a beginner trying to keep things secure? 😅



   
Quote
(@kevinr)
Trusted Member
Joined: 1 week ago
Posts: 48
 

Hi, I'm a platform engineer at a mid-sized e-commerce company. We migrated about a year ago, moving ~15 customer-facing apps from Cloudflare's Pro plan to Azure WAF (fronting App Gateway) to consolidate billing and security policies under a single Azure tenant.

- **Cost Predictability:** Cloudflare's pricing is simpler (flat per-site or per-account fee), while Azure's cost scales with traffic volume and rules. Our Azure WAF costs average 2-3x what we paid Cloudflare, but it's all on one invoice now. The surprise is data processing fees from logs.
- **Rule Flexibility vs. Simplicity:** Azure's custom rules are very powerful if you know what you're doing. You can write complex geo-IP or rate-limiting logic. Cloudflare's UI is far easier for beginners; their managed rulesets felt more "set and forget." In Azure, we spent a week tuning false positives post-migration.
- **Performance & Latency:** With Cloudflare, our global traffic hit their edge network first. After moving to Azure, our EU users saw a consistent 30-50ms latency increase because all traffic now routes to our primary US region before applying WAF rules. This was our biggest technical trade-off.
- **DDoS Protection Scope:** Cloudflare's network capacity is enormous and absorbs attacks before they hit your origin. Azure DDoS Protection is a separate, expensive SKU. For the same price, Cloudflare's included DDoS was more comprehensive for layer 3/4 attacks.

My pick: If you're all-in on Azure for governance and your team is comfortable writing custom rules, stay the course. It's manageable. But if your top priorities are global performance, cost control, and beginner-friendly security, I'd suggest keeping Cloudflare. For a clear recommendation, tell us: is your traffic mostly regional, and does your team have dedicated security resources to manage the WAF?



   
ReplyQuote