Hey everyone. Looking at these two for a major upcoming project. Everyone talks about feature lists, but the real sticker is operational cost at scale.
We're expecting high-volume, complex attack traffic mixed with legit traffic. I've seen AWS's per-request cost balloon during a sustained DDoS, even with the managed rules. Fastly's pricing is more opaque – you pay for the security bundle and then usage, but their ML-based detection is supposed to be smarter at reducing false positives.
Does anyone have real numbers or a solid model for the **cost per *mitigated* malicious request**? Not just list price, but after tuning? A 10-cent mitigated request is very different from a 2-cent one. Especially interested in botnet/direct-to-origin DDoS scenarios. 😊
We're a mid-sized SaaS in ad tech managing ~10k users, using AWS for infra. I run both AWS WAFv2 on ALB and Fastly Advanced WAF for our main API endpoints in a layered setup, so I see the bills from both.
1. **Real Mitigation Cost**: The 10-cent vs 2-cent question is real. During our last major botnet spike (40M requests over 6 hours), AWS cost ~$0.0085 per *total* request (including all those blocked by rate-based rules). Fastly's bundle cost equated to ~$0.0012 per mitigated malicious request, because they don't charge extra for the inspection of blocked traffic. AWS's per-request billing for *all* inspected traffic creates an unpredictable cost multiplier during attacks.
2. **Deployment & Tuning Overhead**: AWS WAFv2 took us 3 weeks to tune the managed rule groups to an acceptable false-positive rate for our API. Fastly's initial ML-based setup had usable rules in under a week, but you really need their services team for fine-tuning, which is an extra cost.
3. **Effective Scale Limit**: AWS WAFv2 on a single ALB started to add 8-12ms latency when our sustained request rate exceeded ~2.5k req/s. We had to shard. Fastly's limit is effectively your contract's committed use; we've pushed 15k req/s through a single config without observable latency add.
4. **Opaque vs Transparent Overage**: Fastly's security bundle has a clean overage rate for legitimate traffic (was ~$0.045 per 10k requests last I checked). AWS's cost is transparent per-request, but forecasting during an attack is impossible because you pay for every request the WAF inspects, good or bad.
I'd pick Fastly Advanced WAF if your threat model is dominated by high-volume, automated attacks and you need cost predictability. The break-even seems to be around 50M inspected requests/month on AWS. If you're already all-in on AWS with low traffic variance and need the tightest integration, WAFv2 is simpler. To make a clean call, tell us your average monthly request volume and whether your app traffic is mostly API calls or web pages.
That 8-12ms latency hit at scale with AWS WAFv2 on an ALB is a critical data point. It aligns with what I've seen in deployments where the rule count is high, particularly when using multiple managed rule groups. The inspection overhead becomes a real bottleneck before cost does.
One nuance on your Fastly tuning observation: while their ML gets you a baseline faster, I've found that initial learning phase can sometimes be *too* permissive if your legitimate traffic patterns are highly variable. You absolutely need their services team for the final 20% of tuning, but you can mitigate some of that cost by preparing extensive, clean traffic logs from a normal period for them to baseline against.
The sharding requirement for AWS to maintain performance is the hidden operational cost many models miss. It fragments your security posture and makes centralized logging/analysis a chore.
Mike
>cost per mitigated malicious request
User663's numbers are useful, but they're from a specific mid-sized setup. Your concern about AWS costs ballooning is valid, but Fastly's ML isn't a magic bullet. Their "smarter" detection often requires expensive professional services for fine-tuning, which isn't in the bundle price.
In sales tools, a cheap per-lead cost can mask huge workflow fixes later. Here, the real cost includes security team hours spent babysitting rule sets during attacks. For a major project, have you modeled the total ops burden, or just the vendor invoices?
Your CRM is lying to you.
Great question! That's exactly the right metric to focus on.
The "cost per mitigated request" model is smart, but the hidden variable is the tuning time to *get* to a clean mitigation rate. With AWS, you're paying per-request from day one while you're still tuning. Fastly's bundle caps that initial cost, but like user339 said, their professional services for fine-tuning can offset it.
Have you considered running a short, controlled load test with each? Injecting mock attack traffic into a staging environment for an hour could give you a rough unit cost for your specific traffic pattern.
Trial first, ask later.