
Overview
The growth of web applications, generative AI, and APIs introduces new vulnerabilities that traditional security solutions struggle to address. Check Point WAF provides web application, generative and agentic AI, and API Protection. The product leverages deep application contextual analysis and an AI-driven machine learning firewall to profile users, monitor application behavior, and detect both known and unknown threats. With over 90% of customers operating in prevention mode and 100% requiring fewer than 10 exception rules, Check Point WAF delivers precise API security while minimizing false positives and simplifying operations.
Advanced Threat Prevention Without Manual Overhead
Check Point WAF provides protection against OWASP Top 10 vulnerabilities, DDoS attacks, API-based threats, and zero-day vulnerabilities - all without requiring ongoing signature updates. Its advanced machine learning firewall capabilities and contextual analysis ensure accurate detection and seamless protection, allowing your security team to focus on strategic priorities rather than managing exceptions.
Optimized for Dynamic Cloud Environments
Built specifically for cloud-native deployments, Check Point WAF integrates natively with AWS services to automate scaling and management. As your applications and APIs evolve, Check Point WAF delivers consistent and reliable web application security without increasing operational overhead. It also supports CI/CD pipeline integration and infrastructure-as-code, enabling API security directly into your development workflows.
Flexible Licensing and Seamless AWS Integration
Check Point WAF is offered as a BYOL (Bring Your Own License) solution, with pricing and entitlements managed directly through Check Point. The underlying AWS infrastructure is billed separately based on standard AWS pricing. This flexibility ensures that CloudGuard aligns with your organizations unique operational and financial needs while maintaining strong integration with AWS services.
Getting Started
To deploy Check Point WAF, click on the "View Usage Instructions" and "Usage Information" below for next steps. For licensing and private offers, contact your Check Point trusted advisor or sales team. AWS infrastructure billing is handled directly through AWS and follows standard pricing models.
Highlights
- AI-Driven Application Security: Protects against both known and unknown cyberattacks including OWASP Top 10 vulnerabilities, DDoS attacks, API threats, AI-driven attacks, and zero-day exploits using AI-powered machine learning. Delivers high efficacy, reduces false positives, and minimizes operational complexity.
- Rapid Deployment and Scalability: Move from setup to active protection within days and gain flexibility for growth for web application, APIs, AI applications and worloads with AWS-native scaling and pay-as-you-go pricing.
- Seamless AWS Integration: Designed for dynamic cloud environments, automates scaling, simplifies management, and integrates natively with AWS services to deliver consistent, reliable web, AI and API security at scale.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Please see seller website for refund details.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Auto Scaling Group
A number of AppSec instances in an Auto Scaling Group. Load balanced by an ELB.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
Additional details
Usage instructions
Navigate to https://portal.checkpoint.com ; if you do not have an existing account, open a new account. Open the main menu (icon is in the top left corner), choose APPLICATION SECURITY under the CloudGuard column, then select Cloud on the left. The Getting Started page will open. After defining the asset, you will be redirected to the Profile page. Note: Obtain the Token for CloudGuard WAF from the Profile page.
Resources
Support
Vendor support
To open a support ticket, send an email to infinity-next-support@checkpoint.com CloudGuard WAF
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Secure filtering and application control have protected web workloads and simplified deployment
What is our primary use case?
What is most valuable?
What needs improvement?
Currently, I have no suggestions for Cisco Secure Firewall . I am not working on the next-generation firewall of Cisco. As I already mentioned, I have no suggestions regarding the features and improvements. I am not working on Cisco firewall currently.
For how long have I used the solution?
Overall, I have been working with Cisco Secure Firewall for almost three to four years.
How are customer service and support?
I would rate the technical support by Cisco a nine out of ten.
How was the initial setup?
I think the implementation is easy. GUI-based implementation for firewalls is straightforward. Although the command line is a very simple process, next-generation firewalls now come with GUI-based interfaces.
What's my experience with pricing, setup cost, and licensing?
In comparison to other vendors, the pricing is reasonable and affordable.
Which other solutions did I evaluate?
I am currently using some Cisco products. I am currently using some switches of Cisco. I am working on the ASA series. I stopped working with Cisco Firewall more than one to two years ago. I am currently dealing mostly with other Cisco products. I am not dealing with Cisco Secure Access or Cisco Duo . I am working with different product vendors such as Check Point and Fortinet. I am working with Check Point Web Application Firewalls and using bundles with them. I am using some features such as WAF and UTP bundles with application controls, web filtering, email filtering, and DNS filtering and controls that are implemented with UTP enterprise bundles and other WAF applications. I have been dealing with Check Point for three to four years on different products. I am using other platforms and testing some things for the networks. I am also using some other products with them.
What other advice do I have?
I did not have new features or functionalities that I have used recently in Secure Firewall. Check Point WAF is used in my company and my customers are using it. I have seen measurable business and security outcomes since implementation of Check Point WAF (formerly CloudGuard WAF) . All vendors design firewalls with application filtering. As per current incident reporting, we implement and update our feature updates and security databases. These databases are updated regularly. Check Point WAF (formerly CloudGuard WAF) works fine for every product like Cisco, Check Point, Fortinet, and Palo Alto. I am currently not using Check Point WAF as a primary solution, just for a specific purpose. Check Point WAF (formerly CloudGuard WAF) is working fine and reports, detects, and stops attacks such as IPS and detection. I would rate Check Point WAF (formerly CloudGuard WAF) a nine out of ten. The existing features are working fine, but new day-to-day attacks and issues arise in the environment globally, dealing with attacks such as phishing and DDoS attacks daily. Check Point WAF (formerly CloudGuard WAF) could improve by addressing the new day-to-day attacks and issues that arise in the environment and globally dealing with attacks. I have been satisfied with pricing, technical support, and performance. I am a customer of Check Point. I have been working in this field for several years. My overall review rating for this product is ten.
Application security has reduced incidents and now needs UI fixes and shared exception rules
What is our primary use case?
We have implemented Check Point WAF (formerly CloudGuard WAF) in our environment. We have been dealing with Check Point WAF (formerly CloudGuard WAF) for three months. We are using Check Point WAF (formerly CloudGuard WAF ) for our company only.
Currently, we are handling only the L7 part with Check Point WAF (formerly CloudGuard WAF), and we are planning to expand to the APIs and rate-limiting capabilities. We are not handling the network part, as we are only taking care of the security part with Check Point WAF (formerly CloudGuard WAF).
We have a team of 15 people who handle Check Point WAF (formerly CloudGuard WAF) and other security aspects. We have only two administrators dedicated to Check Point WAF (formerly CloudGuard WAF).
What is most valuable?
We have seen measurable business and security outcomes since implementation. We have observed reduced incidents with Check Point WAF (formerly CloudGuard WAF).
Check Point WAF (formerly CloudGuard WAF) has helped us reduce our false positives rate. Compared to other WAF solutions, Check Point WAF (formerly CloudGuard WAF) is user-friendly and very visible. When we review incidents with Check Point WAF (formerly CloudGuard WAF), it is clearly visible where the block occurred and it shows us detailed overview of the incident. In other products, I am not able to get the exact reason for the block, so I can identify where the block happened, and it is very user-friendly for me to add the policy or explicit policy there.
What needs improvement?
I face issues with the UI part of Check Point WAF (formerly CloudGuard WAF), as it malfunctions sometimes. Sometimes I do not see the icons in Check Point WAF (formerly CloudGuard WAF), and whenever I refresh the page, the icons remain invisible.
Additional features I have considered with Check Point WAF (formerly CloudGuard WAF) include the ability to add an exception rule. Since we have multiple projects, I want to add an exception rule to all projects as a shared exception, but when adding it, I am unable to add it individually.
For how long have I used the solution?
I have been working in this field for three years.
How are customer service and support?
When I raise any TAC ticket for Check Point WAF (formerly CloudGuard WAF), I am satisfied with their points and their support, as I am receiving immediate responses from the TAC. I can easily rate their support for Check Point WAF (formerly CloudGuard WAF) an eight out of ten.
An incident occurred regarding the Global Accelerator movement from CloudFront to Global Accelerator, and for that, it took one week to respond, which was delayed by five days.
Which solution did I use previously and why did I switch?
We considered the F5 WAF, Edge, and Radware before finally choosing Check Point WAF (formerly CloudGuard WAF).
How was the initial setup?
Compared to others, it was very easy for us to onboard Check Point WAF (formerly CloudGuard WAF) application.
What about the implementation team?
We received nice support from the OEM for Check Point WAF (formerly CloudGuard WAF), so they guided us, and we completed it within a week, onboarding one full project.
What other advice do I have?
The main reason why I chose Check Point WAF (formerly CloudGuard WAF) is about the cost, and we have a Check Point firewall and we also use endpoint security and email security, so we wanted to choose this as a one-stop solution.
I do not have an idea regarding Check Point WAF (formerly CloudGuard WAF)'s ability for preemptively blocking zero-day attacks and detecting hidden anomalies, as it has been only three months, so we are yet to explore things in Check Point WAF (formerly CloudGuard WAF). Currently, we did not check the AI-driven threat detection and prevention capabilities in Check Point WAF (formerly CloudGuard WAF). Are you referring to the Gen AI or the built-in part of the WAF?
Regarding the built-in AI-driven threat detection and prevention capabilities, I do not see any false positive detection based on the AI part in Check Point WAF (formerly CloudGuard WAF), so everything we are receiving is accurate results only. Based on that learning part, when Check Point WAF (formerly CloudGuard WAF) is in learning mode, the learning part is very helpful for us to filter those things, so after moving it to blocking, we are not receiving any false positive alerts or incidents. If I want to add an exception in Check Point WAF (formerly CloudGuard WAF), I can either add it in the shared one or in a local one.
I have given this review an overall rating of 7.5 out of 10.