Radware Cloud WAF is a fully managed Cloud Application Protection Service providing the industry's most comprehensive web application security solution. It integrates Radware's cloud-delivered WAF technology, API protection, Bot management, application layer DDoS protection, client-side protection, analytics, threat detection and security feeds in a single portal.
Radware Cloud WAF is a fully managed Cloud Application Protection Service providing the industry's most comprehensive web application security solution. The service integrates Radware's Cloud WAF, API Protection, Bot management, client-side and application layer DDoS protection in a single portal that provides security analytics, threat detection and real-time security feeds to protect applications against hacking, malicious bots, API exposure, Web DDoS attacks, supply chain attacks and other vulnerabilities.
Radware's combination of negative and positive security models provides a complete level of protection against OWASP Top 10 threats and zero-day attacks.
API Discovery and Protection - End-to-end API solution from Discovery to protection at a click of a button. Radware auto API discovery maps all of your applications documented and undocumented third-party APIs, automatically generates Open API schema files, generates tailored security policies to detect and block API-focused attacks in real time and enforce protection across all your APIs. Radware's advanced API protection eliminates your documenting and protecting APIs overheads and keeps your organization protected across the board.
Bot Management - Integrated Bot Manager provides comprehensive mitigation options, such as Blockchain-based Crypto challenges to counter attacks. It ensures precise bot management for web, mobile, and API traffic by employing behavioral modeling, collective bot intelligence, and fingerprinting. This defense guards against all OWASP 21 automated threats, including account takeover, credential stuffing, DDoS, fraud, and web scraping, fortifying online operations.
Web DDoS Protection - Industry leading application-layer L7 protection against DDoS attacks, based on Radware's unique machine-learning-based behavioral detection that distinguishes between legitimate and malicious traffic, and automatically generates granular signatures in real-time to protect against zero-day attacks. Best-in-class security against a wide variety of threats, including HTTP Floods, HTTP bombs, low-and-slow assaults, Brute Force attacks, and disruptive web DDoS Tsunamis.
Client-side Protection - Easily block requests to suspicious third-party services in your supply chain and adhere to data security compliance standards. Protect against client-side attacks coming from third party JS services - Formjacking, Skimming,Magecart, automatically and continuously discover all third-party services in your supply chain with detailed activity tracking, as well as get alerts & threat level assessment according to multiple indicators, including script source and destination domain.
Pricing
We have 3 different pricing packages - Standard, Advanced and Complete. The Standard and Advanced packages come with some of the features while Complete provides full coverage.
Highlights
Fully Managed Web Application Protection Service - 24x7 Fully managed security service by Radware's expert Emergency Response Team(ERT). Protect Against OWASP Vulnerabilities - Stay protected against 150+ known attack vectors, including the OWASP Top 10 Web Application Security Risks, Top 10 API Security Vulnerabilities, Top 21 Automated Threats To Web Applications, and Top 10 Client-side vulnerabilities
Detect, Manage and Mitigate Bots - Detect and distinguish between good and bad bots to protect websites, mobile apps and APIs. Easily optimize and customize your bot management policies to provide a better user experience and drive more ROI from your application traffic. End-to-end API Protection - From discovery to enforcement at a click of a button, Radware combines behavioral analysis and policy automation to protect from increasingly sophisticated API assaults.
Mitigate Application-Level DDoS Assaults - Radware's DDoS protection technologies provide the shortest time to detection and mitigation of most advanced and high volume HTTP-based DDoS assaults by utilizing patented behavioral analysis, machine learning-based engines. Protect Client-Side From Supply Chain Attacks - This solution offers advanced client side protection that ensures the protection of end users data when interacting with any third-party services in the application supply chain.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is usage-based and measured in Mbps of legitimate bandwidth. You start with a base Cloud Application Protection plan in three levels: Standard, Advanced, and Complete. Standard sizes by throughput (10, 50, or 100 Mbps) for one application. Advanced and Complete cover 10 Mbps for one application, with per-application add-ons to expand coverage. On top of any base plan, you can layer independent add-ons billed separately. These include CDN enablement, Cloud DDoS Protection (on-demand or always-on), Web DDoS, Firewall as a Service, Network Analytics, AI SOC Xpert, Access Logs, LLM Firewall, PCI DSS compliance, ERT Premium support, extra protected networks, and the SecurePath connector.
Top-of-mind questions for buyers
What does one Mbps of legitimate bandwidth mean for billing?
Pricing meters legitimate traffic bandwidth, measured in Mbps, not attack or blocked traffic. Your base plan is sized to a bandwidth tier, and many add-ons are also priced against legitimate bandwidth blocks, such as 10Mbps or 200Mbps units. Attack traffic that the service filters out does not count toward your metered bandwidth.
How do the base plan and add-ons combine on one bill?
You pick one base Cloud Application Protection plan, then layer optional add-ons that each bill separately. Charges add together, so your total is the base plan plus every add-on you select. Per-application add-ons extend coverage one application at a time. Bandwidth-based add-ons bill in fixed blocks, like 10Mbps or 200Mbps.
How do the On-Demand and Always-On Cloud DDoS Protection options differ for cost?
Both meter legitimate bandwidth in 10Mbps units. On-Demand DDoS Protection engages only when mitigation is triggered, suited to occasional attack response. Always-On keeps protection active continuously, suited to constant exposure. You choose one model per subscription, and each is billed monthly against your legitimate bandwidth.
www.radware.com
Helpful?
Vendor refund policy
No refund offered
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Online Support Service Portal -Appropriate for non-critical issues, such as general inquiries, requests for technical documentation/ information, schedule support during an upcoming maintenance window, view installed base and manage support cases.24x7, where Internet service is available
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Alteon VA supports the complex functionality requirements of Enterprise applications which go beyond basic availability and quality of experience features. These include: Layer 7 Rewrite, Application Level Traffic Steering, Caching, SSL Offload, compression, acceleration. WAF (AppWall), SecureUR L
Cloud Native Protector provides an agentless, cloud-native solution for comprehensive protection of AWS assets, to protect both the overall security posture of cloud environments, as well as protect individual cloud workloads against cloud-native attack vectors
Radware API Security Service delivers end-to-end API protection through continuous API discovery, runtime posture management, contextual testing, and AI-driven defense. It helps organizations identify exposed or misconfigured APIs, reduce risk, and protect against business logic abuse, automated threats, and DDoS attacks across modern application environments.
Service has kept frequent attacks under control and provides strong protection every day
Reviewed on Sep 22, 2026
Review provided by PeerSpot
What is our primary use case?
I have some experience with Radware Cloud WAF Service, as I obtained your contact information from Radware.
I would be interested in leaving feedback about Radware Cloud WAF Service because I appreciate all aspects of the service. All of the service is very helpful for us, but we are currently evaluating whether we will continue with this service.
I have been using Radware Cloud WAF Service for three years.
What is most valuable?
What I appreciate the most about Radware Cloud WAF Service is the security that we have. It is something we need greatly, and it is very helpful for us. We experience many attacks constantly, and because of the service, we remain secure.
Radware Cloud WAF Service does an excellent job at blocking unknown threats and attacks.
What needs improvement?
I think Radware Cloud WAF Service could improve with application notifications. That would be very helpful.
I expect to receive notifications when I have an incident or anything to check.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for three years.
What do I think about the stability of the solution?
Regarding stability, we have received some notifications, but we did not actually notice any issues.
What do I think about the scalability of the solution?
I think Radware Cloud WAF Service is scalable because we experience perhaps one or two days every semester when we have some peaks in service demand, but we did not encounter limits on the service. It scales up automatically, and it did not cut the service for us. That is a very good thing, because it is not constant—it occurs only two to four days per year.
How are customer service and support?
I have contacted the technical support of Radware twice in three years when we needed some configuration.
My experience with the quality of the support and the speed of response was quick.
I think the quality of the support is good. It is a good service.
If I were to rate them on a scale from one to ten, I would give the support a score of ten.
Which solution did I use previously and why did I switch?
I have not used any alternatives or similar solutions to Radware Cloud WAF Service in the cloud.
How was the initial setup?
The initial deployment of Radware Cloud WAF Service was easy.
It took me approximately a couple of days to deploy it for the first time.
What about the implementation team?
Approximately three persons were involved in the deployment of Radware Cloud WAF Service.
What other advice do I have?
I am thinking of moving away from Radware Cloud WAF Service.
I am considering moving away from Radware Cloud WAF Service because of the price. I love the service, but the price is very expensive for us. We have to renew the service, but we are evaluating some alternatives because of the cost.
Radware Cloud WAF Service does not require any maintenance on my end.
I do not use the API Discovery feature.
I do not use any CDN services or Content Delivery Networks.
I think the reporting and analytics provide a good reporting service.
I would give this review an overall rating of ten.
Mukesh K.
Outstanding Security, Seamless Setup
Reviewed on Sep 15, 2026
Review provided by G2
What do you like best about the product?
I really like the effective threat detection and automatic mitigation capabilities of Radware Cloud WAF. The user-friendly dashboard and real-time visibility are fantastic as they reduce operational effort and significantly improve overall security. I also find the initial setup to be simple and quick, with a user-friendly interface that requires minimal configuration effort. These features make managing our web applications' security straightforward, which is exactly what we need.
What do you dislike about the product?
Radware Cloud WAF is highly effective, but reporting customization and detailed log analysis could be improved. Enhanced third-party integrations would also provide a better overall management experience. I would like more customizable dashboard and reporting options. More customizable reports, better log filtering, and faster search capability would make it easier to investigate security events.
What problems is the product solving and how is that benefiting you?
I use Radware Cloud WAF to protect our web applications from cyber threats, improve security, maintain application availability, and reduce operational efforts with its effective threat detection and real-time visibility.
Bryan M.
Excellent API protection and schema discovery, ideal for GraphQL
Reviewed on Sep 08, 2026
Review provided by G2
What do you like best about the product?
I like the protection it offers for APIs and API schema discovery, especially when creating GraphQL.
What do you dislike about the product?
When something new comes out, it takes a while to inform the public. It appears on the portal, and until one notices it says 'new', one needs to investigate on their own.
What problems is the product solving and how is that benefiting you?
The attacks targeted at the organization are now much better covered. With the AI module, the solution is further strengthened as it allows detecting potential AI-orchestrated attacks and offers protection for LLM models. Additionally, the reinforcement in API Protection is another plus that adds to the strength of cybersecurity.
Moisés M.
Excellent Web Security with an Intuitive, Clear Traffic Dashboard
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
Radware Cloud Application and API Protection provides excellent security for our web assets. The dashboard is intuitive, and it offers clear, easy-to-understand visibility into incoming traffic, which helps us monitor what’s happening at a glance.
What do you dislike about the product?
Tuning the system to minimize false positives requires continuous monitoring and manual adjustments, especially during the initial deployment phase or when launching new API endpoints.
What problems is the product solving and how is that benefiting you?
By using behavior-based intelligence to automate threat detection and policy updates, it helps our organization maintain continuous service uptime, reduce the need for manual security management, and keep performance smooth for legitimate users.
Luis Alexander Velez B.
Web protection has reduced municipal incidents and provides clear visibility into global attacks
Reviewed on Sep 02, 2026
Review from a verified AWS customer
What is our primary use case?
Radware Cloud WAF Service is a tool for controlling the websites of the Municipio de Quito, and I have significant visibility with the tool.
For example, on two principal sites of Quito, I have implemented geo-blocking policies, and I can detect attacks from China, Russia, and other locations. I have visibility for these attacks, and this is a fundamental tool to protect the municipality.
How has it helped my organization?
Radware Cloud WAF Service has positively impacted my organization by stopping attacks such as SQL injection attacks and geo-blocking attacks, which appear frequently in the tool logs.
I have experienced a reduction of incidents in my organization since we started using it.
What is most valuable?
I use a WAF which stands out as one of the best features Radware Cloud WAF Service offers.
It is focused on web services, and the API is a very recent proof of concept; I do not currently have features for web services. With Radware Cloud WAF Service, strong behavior, threat detection, and automated policy synchronization are features that could make it even better. I also observe DDoS protection and visibility of the forwarding and system logs.
I assess Radware Cloud WAF Service for blocking unknown threats and attacks, primarily with threats such as geo-blocking and OWASP compliance, as well as SQL injection. I do not currently see other threats in the logs.
What needs improvement?
Radware Cloud WAF Service is easy to use, and configuring and monitoring the logs is straightforward.
I do not currently have integration with a SIEM, but I have a SIEM integration planned for the next two months as I implement new tools to complete my cybersecurity area.
To reduce false positives from geo-blocking, I maintain a list of public IPs. I currently experience many false positives with my front-end firewall, as I do not have a geo-blocking solution in this firewall, but I have reduced these false positive issues.
For how long have I used the solution?
I have been working in my current field for almost three years.
What do I think about the stability of the solution?
I do not have anything to add about my main use case or how I interact with Radware Cloud WAF Service. I have a proof of concept for APIs in Radware Cloud Services, but it is not yet complete.
What do I think about the scalability of the solution?
I am currently only integrating this and have no other implementation.
How are customer service and support?
I work with a partner; my company does not have a business relationship with this vendor other than being a customer.
Which solution did I use previously and why did I switch?
I do not have additional thoughts about Radware Cloud WAF Service.
How was the initial setup?
The integration is simple and easy with my sites.
What about the implementation team?
The purchase is not directly through a partner; I work with two partners, and they purchased and passed the licenses to the government entity.
What was our ROI?
It is easy for my team, and it has reduced incidents.
What's my experience with pricing, setup cost, and licensing?
I have a process to purchase additional features or services for Radware Cloud WAF Service.
Which other solutions did I evaluate?
I have the configuration for SIEM logs, and I need to complete the proof of concept of the API Discovery Automate.
What other advice do I have?
The advice I would give to others looking into using Radware Cloud WAF Service is that it is a tool for my business.
Radware Cloud WAF Service remains a great solution that shines in high-security, high-throughput environments where behavioral detection and hybrid multi-cloud deployment flexibility are top priorities. My overall rating for this review is ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?