Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

CloudGuard WAF

Check Point Software Technologies | v1.2406

Linux/Unix, Other Gaia 3.10 - 64-bit Amazon Machine Image (AMI)

Reviews from AWS customer

2 AWS reviews
  • 5 star
    0
  • 2
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

48 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Mantu Shaw

Achieved improved security compliance with comprehensive visibility across cloud environments

  • April 30, 2025
  • Review provided by PeerSpot

What is our primary use case?

We have over ten root domains that we need to protect through the firewall. All our hosts are in EC2 instances, and it is challenging to protect them by using any AWS load balancer or shields. Therefore, we have implemented Check Point CloudGuard WAF as a solution to protect all these domains from the open internet. It supports all environments, including on-premises, Azure, AWS, and we have also implemented it for CDN URLs as well.

How has it helped my organization?

It has improved the overall security posture of our organization. Earlier, our security score was around eight to nine, which increased after implementing Check Point CloudGuard WAF. We have achieved NIST compliance, and now ninety-five percent of the environment compliance level is equal to ninety-five percent.

What is most valuable?

The support of the root domain is one of the best features, as is the support for the CDN and advanced load balancer. These are key features that differentiate Check Point CloudGuard WAF from other vendors. Additionally, rate limiting is another significant feature of the WAF.

What needs improvement?

The UI interface needs improvement because there are a number of bugs. Integration with the SIEM platform is currently one of the key challenges that need to be addressed.

For how long have I used the solution?

We have been using Check Point CloudGuard WAF for the last six months.

What do I think about the stability of the solution?

I think Check Point CloudGuard WAF is stable.

What do I think about the scalability of the solution?

It is a SaaS-based model, and we have not encountered any scalability issues. They have sufficient resources, and there are no challenges from a scalability perspective.

How are customer service and support?

The customer support is good. They have skilled personnel to provide support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not use a different solution prior to this.

What was our ROI?

The return on investment is reflected in the improvement of the overall security posture. While it does not have a direct monetary impact, it enhances security with an improved NIST compliance score and better overall security scores for our organization.

What's my experience with pricing, setup cost, and licensing?

Pricing and setup costs are fine. It is less costly than Cloudflare, Fortinet, and other vendors. Additionally, it is less costly than the OEM.

Which other solutions did I evaluate?

We evaluated Cloudflare and Fortinet.

What other advice do I have?

I would advise others to use and implement Check Point CloudGuard WAF as a solution in the firewall segment. Check Point has been in this segment for two decades and is more stable than other firewall vendors. I recommend using it and implementing all the features it offers. Overall, it's a good solution, and it fulfills all our core purposes, providing complete visibility and security. That's why I rate it ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    Mantu S.

unified gateway level security solution for All Web, API application.

  • April 29, 2025
  • Review provided by G2

What do you like best about the product?
Easy to integrate, support of all use case like root domain mapping, auto discover of API endpoints, Rate limiting of web traffic, customization based on integrated assets. easy to Integrate.
What do you dislike about the product?
Quick Support is a only pain for checkpoint
What problems is the product solving and how is that benefiting you?
Protection of all incoming web traffic, DDoS Attack, securing over exposed API.


    Information Technology and Services

Reliable Threat Prevention for Web Apps and APIs

  • April 29, 2025
  • Review provided by G2

What do you like best about the product?
I really like how easy it is to deploy in the cloud and how it just works with AWS and Azure. It blocks threats before they get near our apps, and the real-time alerts are super helpful.
What do you dislike about the product?
While CloudGuard WAF is effective, the initial configuration and policy tuning can be complex, especially in environments with custom applications. The user interface could also be more intuitive when managing large rule sets or viewing logs.
What problems is the product solving and how is that benefiting you?
"Check Point CloudGuard WAF helps us secure our web applications and APIs against common and advanced threats like SQL injection, cross-site scripting, and bot attacks. It addresses the challenge of protecting dynamic, cloud-native workloads by integrating directly with AWS and Azure. The benefit is real-time protection with automated scaling and consistent policy enforcement across our cloud environments, significantly reducing the risk of breaches and downtime.


    Satish P.

CloudGuard WAF Delivers Peace of Mind and Similipfied

  • April 23, 2025
  • Review provided by G2

What do you like best about the product?
1 ) Accurate threat detection with minimal false positives
2) Prevention First approach
3) Reduces operation overhead
4) Good detection technology
5) Minimal false positive
6) Onboarding is easier
7) Best feature is its comprehensive API security and automated API discovery
What do you dislike about the product?
1) Initial onboarding is tedious
2) Documentations needs further improvement
3) Drastic improvements needs in support
4) Need further improvement in antibot
What problems is the product solving and how is that benefiting you?
Zero-day threats, API risks, operational complexity—with AI-driven automation, precise threat prevention, and seamless cloud integration. This resulted in stronger security postures, lower operational costs, and scalable protection.


    José Luis C.

Protecting your brand with Check Point CloudGuard

  • April 22, 2025
  • Review provided by G2

What do you like best about the product?
The automation of rules and the visibility of logs by category
What do you dislike about the product?
The initial setup was a bit complicated having an AWS behind it.
What problems is the product solving and how is that benefiting you?
Automatic reputation protection on a CMS developed in WordPress


    Dialungana M.

Cloudguard WAF protects our critical web applications and APIs

  • April 22, 2025
  • Review provided by G2

What do you like best about the product?
It does not require too much manual configuration and it is straight forward to set it up and get your critical assets protected against sophisticated attacks using AI and machine learning to automatically understand the behavior of our applications and APIs.
What do you dislike about the product?
The fact that you cannot have two assets with the same URL even though the application is reached using different IP addresses.
What problems is the product solving and how is that benefiting you?
Before we had no visibility into the application layer attacks targeting our web applications and APIs. We relied completely on our Next Generation Firewalls (NGFW) to protect our assets. Ever since we deployed Cloudguard WAF, we immediately understood that we were missing many attacks that were targeting the applications. Today, with Cloudguard WAF, we block an average of 3500 attacks on daily basis. In addition to that, with tha API protection, we are now able to identify all the endpoints associated with the applications and better protect our APIs.


    reviewer2647476

We get a consolidated view, good security, and excellent scalability

  • February 05, 2025
  • Review from a verified AWS customer

What is our primary use case?

I have a team that manages CloudGuard for me. We have different research centers using various cloud accounts and are trying to consolidate everything into a single landing zone to protect those areas. From a use-case perspective, I have different laboratories or research centers utilizing it for various purposes. We are mostly focused on AI, and some of those requirements cater to the AI segment as well.

How has it helped my organization?

From a protection perspective, Check Point is a well-renowned name. We are also using other products from Check Point, such as Harmony, Infinity, and XDR. We have a consolidated view of the overall security posture, which I find quite interesting.

CloudGuard WAF protects our applications against threats without relying on signatures. This is crucial for us to maintain application security and stop the threats coming into our environment, keeping our production part secure.

Check Point CloudGuard WAF works well for preemptively blocking Zero Day attacks and detecting hidden anomalies. It is the best. That is why I am paying for it.

Check Point CloudGuard WAF helps us with overall application and cloud API security. The consolidated view of the security posture that Check Point provides is very useful from an upper management perspective.

CloudGuard WAF has helped reduce our false positive rate by 30%.

What is most valuable?

From a security perspective, it is quite good. I am not very familiar with the detailed features of it because I have a team that manages it. 

What needs improvement?

I am pretty happy with the current version. I have not yet used it to its full potential, but there could be improvements as I explore it further. I am content with what I have in terms of features and support, but if I start expanding the usage, I might need more help from them. I already have the best consultants from Check Point. 

For how long have I used the solution?

I have been using this solution for around seven or eight months now.

What do I think about the stability of the solution?

I have not observed any stability issues yet. It has been pretty reliable.

What do I think about the scalability of the solution?

The scalability is excellent and is one of its best features.

How are customer service and support?

Customer service is one of the best in the market right now.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not use a similar solution previously. 

How was the initial setup?

We have a hybrid deployment model with AWS as the cloud provider. 

Its deployment was smooth. We did not have any issues. 

What about the implementation team?

We used Check Point for the implementation.

What was our ROI?

It has been only six or seven months now. I am hoping that by the time I complete one year, I will see the return on investment.

It has reduced the total cost of ownership for our web application firewall to a certain extent, but I do not have the numbers.

What's my experience with pricing, setup cost, and licensing?

The sales team or account managers from Check Point are top-notch. As I am using other products as well, my pricing was competitive compared to others.

Which other solutions did I evaluate?

I considered other solutions. I decided on Check Point because of its comprehensive suite of applications and the integration with my tools, providing a consolidated view of my security posture.

What other advice do I have?

I would rate Check Point CloudGuard WAF a nine out of ten. I believe there is always room for improvement, but there are use cases I have not yet explored. 


    Dialungana Malungo

Protects our web applications and APIs and has a very low false positive rate

  • February 05, 2025
  • Review provided by PeerSpot

What is our primary use case?

We have been looking for a solution to protect most of our web applications, especially because we have a couple of them available on the Internet. 

We are not looking at just the web application but also APIs because as a Telco company, we have a mobile money service and some other services that are API-based. We needed a solution that does not only look at our web applications but also our APIs. When I found out about CloudGuard WAF, it was a perfect match. It could not only protect our web application, but we were also able to protect our APIs. We have a couple of APIs on the Internet.

How has it helped my organization?

CloudGuard WAF has been great. We had no visibility when it came to our web application because, back then, we only had the next-generation firewall. We were able to protect some network-level attacks, but we had no visibility into what was happening at the application level. What we see now is unbelievable. We are talking about 800,000 attacks that we could not prevent before or were not even aware of, whereas now, we get them every day, and it is CloudGuard WAF that protects us against most of them.

CloudGuard WAF has reduced our false positive rate. That was one of the advantages of the solution itself. False positives are one of the main issues that we have with most security solutions, especially because each application has its own way of working. If the solution is not being able to learn how your applications work, there are going to be a lot of serious issues. With CloudGuard WAF, we did not have much of this issue. We never had an issue where something stopped working because of CloudGuard WAF. Whatever was prevented was actually malicious, so we have a very low rate of false positives. 

What is most valuable?

CloudGuard WAF is a very straightforward solution. I do not have to worry about signatures. Most of the solutions that are out there are mainly based on signatures, and I have to do a lot of maintenance to get the signature updates, and sometimes, due to a lack of resources, I am not able to do so. With CloudGuard WAF, I have peace of mind, because most of the features are AI-based, and there is not much configuration that needs to be done on my side. Once set, I only go to CloudGuard WAF to check. I do not have to worry about signatures or updates. Everything is done perfectly, and I have a sense of peace because I know our applications are safe. 

It is very important for us that CloudGuard WAF protects our applications against threats without relying on signatures. That is definitely one of the key features I need.

What needs improvement?

We are satisfied with the product because it does what we need it to do, but one thing that I would like to see improved in the product is the protection of our mobile applications. When I migrate the traffic from our mobile application to CloudGuard, we are not getting what we expected. We would like to be able to also look at our mobile applications.

For how long have I used the solution?

I have been using Check Point CloudGuard WAF for three years.

What do I think about the stability of the solution?

It is very stable. We run some of the agents on our data centers and never had any issues. We are happy with the solution.

What do I think about the scalability of the solution?

It is completely scalable.

How are customer service and support?

Technical support is very nice. I have encountered a couple of issues related to the solution. They were not actual issues but things that needed clarification, and support was always there. They gave me the right reference to solve the issues that I faced. I do not have any complaints about the support and customer service aspects.

I would rate them an eight out of ten. They have very short working hours. Especially on the weekends, when you call them, the team is not working because they are a very small team. They need to increase the number of people for 24/7 support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were using Check Point's next-generation firewall. We are heavily Check Point customers.

What was our ROI?

When it comes to monitoring the solution, I do not have to worry that much about the solution itself. We have the peace of mind that the solution is doing what is expected from us. We do not have to worry much about the solution itself.

It is doing what it is supposed to do, and I do not need people to look at it 24/7. Most of the operations happen in the background, so I do not spend much time on it.

What's my experience with pricing, setup cost, and licensing?

As Infiniti customers, the pricing is manageable, as we have allowances dedicated to each Check Point product. The price is not as high compared to other options I have dealt with in the past. 

Regarding the reduction of the overall total cost of ownership, I am not deeply involved with cost management. However, feedback from a senior manager indicates that we have made a positive decision.

Which other solutions did I evaluate?

When we were choosing the solution, we had a couple of vendors. After assessing the advantages of each solution, we found Check Point CloudGuard WAF to be the perfect match for my needs.

First of all, there are no signatures. We do not have to rely on signature updates. That was the main reason. Also, it does not only focus on our web application; it also focuses on our APIs. We have got a couple of them.

We, as a company, focus on consolidation. Instead of having siloed solutions separately where people have to look at different solutions, we focus on consolidation. Being able to have another solution that is consolidated and integrated with the other ones we had was a perfect match for us.

What other advice do I have?

I would rate Check Point CloudGuard WAF a nine out of ten.


    Charalampos Symeou

Ensuring customer security with comprehensive protection and responsive support

  • February 04, 2025
  • Review provided by PeerSpot

What is our primary use case?

I use CloudGuard WAF for our exposed customer-facing servers.

How has it helped my organization?

It provides security for our customers and our products.

What is most valuable?

This solution not require training. It has its own mechanisms, eliminating the need for training for our applications. The learning curve is quick.

It provides security for our services to customers. As a financial institution, we provide security to our customers and products.

The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively.

The solution reduced the cost to the company when considering that we,with a previous solution, spent many hours on configurations.

It reduced our false positive rate significantly - by 90%.

What needs improvement?

The reporting can be improved. Currently, it is not 100% accurate, however, it is at a good level. I cannot see many logs for our application that are posted under CloudGuard WAF, and sometimes I cannot identify the issues I have with CloudGuard.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

The stability is 100%. I did not have any issues in the last three years during which I had more than ten critical services running on CloudGuard.

How are customer service and support?

Customer support is usually needed during the implementation of the solution. After that, I have only opened a case two or three times, and the response time is very good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I had the same solution with the same company, however, it was on-premise. I moved to a cloud-based solution with CloudGuard WAF, and it is very different.

How was the initial setup?

When considering my previous solution, I spent many hours on the configuration.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are really expensive for this product. While it provides a very good security level, the price for each service is high. Small organizations might not be able to afford the price.

What other advice do I have?

I would rate the solution nine out of ten. Overall, it is a very good solution. 

Which deployment model are you using for this solution?

Public Cloud


    Thanos Constantopoulos

Real-time attack recognition and integration provide peace of mind while safeguarding websites

  • February 04, 2025
  • Review provided by PeerSpot

What is our primary use case?

Protecting our websites or our customers' websites is our top priority. We transitioned to Check Point WAF from on-premises WAF to safeguard our external perimeter. Essentially, I am focused on protecting our external infrastructure and web services.

How has it helped my organization?

It helps me sleep at night, providing peace of mind. It saves time, money, troubleshooting, and maintenance and reduces the need to hire people to manage the technology because it is so easy to use.

What is most valuable?

The WAF is the best feature. The application firewall's ability to block and recognize all attacks in real-time, such as DDoS, is invaluable. Identifying attacks and integrating with the rest of the ecosystem are features I am very fond of.

It's a pretty robust product.

CloudGuard protects against threats without relying on signatures. This is one of the best features. As an engineer, I don't have to review signatures one by one by one. 90% of the other players use signatures. So you have to review the attack, the signature, and how to mitigate it, etcetera. Removing the signatures from the equation removes a lot of time required for an engineer to review signatures, apply signatures, verify that these are applied to the infrastructure, etcetera. So removing that from the equation and protecting the infrastructure at all times is very cost-effective. 

Signature-based also causes a lot of false positives. So having no signature also helps remove a lot of the false positives. 

What needs improvement?

I cannot think of any needed features.

Pricing is high, although possibly justified by the service received. Reducing prices would be welcome. 

Integration with more technologies or Check Point products, or on-prem products, could improve robustness. Many organizations are moving to the cloud. Some cannot fully transition and require solutions similar to on-prem devices. 

For how long have I used the solution?

I have used the solution for the past two years.

How are customer service and support?

Support is the same with on-premise devices, and it is very good. Since it is cloud-based, I do not need them as much. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used CloudGuard, Imperva Cloud WAF, and Barracuda Cloud WAF. I have experience with all of the major players.

What was our ROI?

I have seen what we were used to before and how much time we spent. We used to manage on-prem devices for other partners that could run from other vendors. When you migrate to the cloud, it feels like saving 90% of your time.

What's my experience with pricing, setup cost, and licensing?

If the price could come down, I would be very happy with the product.

Which other solutions did I evaluate?

I will not disclose which vendor is the best. In specific cases, some vendors perform well, while others are competitive at the high end. Check Point is one vendor that I really appreciate, and I will not mention the other, however the competition is very close.

What other advice do I have?

I would rate the solution nine out of ten. Nobody is perfect.