We use Radware Cloud WAF Service for WAF protection and API protection.
Radware Cloud WAF
RadwareExternal reviews
External reviews are not included in the AWS star rating for the product.
Reliable Shield for Web Apps
Strong Web Application Security
Radware WAF Cloud: A Web Application Security Platform
Has managed high traffic efficiently and reduced false positives while maintaining strong API protection
What is our primary use case?
What is most valuable?
The best features of Radware Cloud WAF Service are its ability to manage high traffic, its scalability, and its reliability. Whenever we observe any detections or unusual traffic at a high rate, Radware manages the replication of web applications in such a way that no web applications are ever hampered, ensuring all traffic is managed effectively.
Radware Cloud WAF Service has significantly reduced our false positives, as Radware keeps its policies up to date with emerging tactics. This has led to very few false positives, which is one reason we have chosen to implement Radware WAF in our environment, given its favorable false positive ratio.
What needs improvement?
In Radware Cloud WAF Service, the areas that have room for improvement include the costing part, as we faced some issues during the implementation and POC of this WAF technology.
Additionally, the policy management can be improved, along with the graphical user interface for better visualization, so any new user can adapt to its graphics and find it easier to use.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for around three plus years.
How are customer service and support?
I would rate the support a perfect 10 out of 10 because the support is good.
What was our ROI?
We have seen a good amount of return on investment with Radware Cloud WAF Service, roughly 50 to 60%. By reviewing our alerts and traffic, we can assess what traffic has been blocked and how much it has saved our applications and infrastructure.
Given our critical web applications and our substantial environment, where many applications are onboarded on WAF, overall, we can say it has yielded good returns on investment.
Which other solutions did I evaluate?
When I compare Radware Cloud WAF Service with other WAF software, I notice that while Radware's technology is strong, the only cons we faced were related to costing and some policies. Other solutions are available in the market, but they also have their drawbacks.
What other advice do I have?
We use the CDN services offered by Radware with Radware Cloud WAF Service. The combination of CDN and Radware Cloud WAF Service is easy to use, and the security it offers is good, especially with the WAF plus DDoS integration, which is ideal for media and all types of streaming.
I assess Radware Cloud WAF Service for blocking unknown threats and attacks as effective because it updates its mitigation policies with day-to-day strategies, incorporating new and emerging tactics. Additionally, it blocks some traffic based on AI, which enhances its ability to manage intrusion threats.
The automated analytics for looking at events is positive, as it has inbuilt automations that reduce our manual intervention. Due to this, there is a quick incident response in case of any high alert or critical case, ensuring that proper mitigations have been taken care of for any incident, which allows for a rapid response over any alert.
Radware Cloud WAF Service for integrating with other systems and applications in our business is seamless, as we have integrated Radware WAF with our SIEM monitoring tool, Microsoft Sentinel. We can get centralized logs for every tool on Sentinel, and it was easy to implement and integrate with it. Throughout the integration with Sentinel, we received excellent support and good documentation.
I assess Radware Cloud WAF Service for its ability to protect against zero-day attacks as competent since it adapts behavioral models. If it observes any vulnerability that Radware WAF hasn't recognized in its recent models, it trains its models based on behavior to manage zero-day exploits, ensuring that if any sudden bot traffic or API abuse occurs, Radware mitigates it and blocks all such traffic effectively.
The combination of negative and behavior-based positive security models is crucial for our organization's security strategy because Radware assumes everything is allowed unless it observes any malicious activity or anomaly. In such cases, WAF only blocks when something malicious or specific signatures are observed, making it reliable for our applications and ensuring none are hampered by any false positives.
We use Radware Bot Manager. With Radware Bot Manager, we have discovered issues such as web scraping and DDoS bots from our incoming bot traffic that we weren't aware of before, as it provides detections for that and actively blocks all such DDoS traffic and bot traffic based on its AML algorithms. We have also enabled API bot protection.
We use the web DDoS protection offered by Radware. Radware Cloud WAF Service has helped in our business continuity by ensuring that no legitimate traffic is blocked. Only when something suspicious based on L3, L4, or L7 DDoS attacks or such signatures is observed does Radware block malicious traffic, guaranteeing reliability and continuity for our web applications.
The solution requires maintenance when we want to configure or tweak any policy, which is when we seek support from the tech team.
Our team includes 30 engineers who use Radware WAF. We will recommend this product to other users because we have suggested it to our peers. Looking at the solution this tool has provided us, we find it beneficial enough to promote it to others.
On a scale of 1-10, I rate this solution a 9.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Reliable WAF Solution
Strengthens API threat detection and helps meet compliance during security investigations
What is our primary use case?
My use case for Radware Cloud WAF Service is that we have Radware as one of our products for security protocols that we have established at our organization. Whenever there is a cloud security alert, we check Radware services so that we can mitigate the alerts.
What is most valuable?
What I appreciate the most about Radware Cloud WAF Service is the API management. The API information that they provide is excellent. The hidden and non-discoverable APIs information available with Radware Cloud WAF Service is really great.
I cannot share some important details of the incident that we received. That said, thanks to this feature, we were able to mitigate a threat. The information they provide and the discovery they do really help us out in some incidents.
They also help us meet compliance requirements. Being a big organization, we have to meet certain compliance standards, and for the PCI DSS, this product really helps us out.
Radware Cloud WAF Service is a comprehensive tool, and my functionality with it is limited as I'm working on multiple things at a time as a security consultant. In our organization, only specific tasks are assigned to a single individual. That's why I'm primarily focused on API security and sometimes DDoS attacks.
Radware Cloud WAF Service integrates very well with other applications and services; we have Microsoft TI tool with us, and it's integrated efficiently. We receive the alerts on time.
Regarding zero-day attacks, we are fortunate that we haven't received any as of now. For API security, I have closely seen how Radware Cloud WAF Service has helped us twice this year.
We use Radware Cloud WAF Service for our security purposes. We have a symbiotic relationship with Radware Cloud WAF Service. They provide us with information and necessary security steps, and we use it for our investigation or threat hunting.
What needs improvement?
As for the downsides of Radware Cloud WAF Service, I would surely appreciate some AI integration with report management. Whenever we handle an incident, we have to generate many reports. We have to get data, information, and screenshots on multiple things. A future feature in Radware Cloud WAF Service that could give us a presentable report for our stakeholders would be a really great addition.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for about 18 months.
What do I think about the stability of the solution?
I have never seen any lagging, crashing, or downtime with Radware Cloud WAF Service.
What do I think about the scalability of the solution?
The cloud engineering team has told us it's really scalable. Whenever we deploy something or integrate this, it's really flexible with the DevOps and DevSecOps teams.
How are customer service and support?
I have never contacted the technical support or customer support. We have communication through emails; nothing very technical.
How would you rate customer service and support?
Positive
How was the initial setup?
The learning curve for using Radware Cloud WAF Service is very easy. There is nothing too complex about it.
We have these Radware information sessions and emails coming up to tell us the latest about what's happening in the cyber environment. They provide information on basic concepts and where to find it in the emails. Even a beginner can learn it within ten days.
Radware Cloud WAF Service does not require any maintenance on my end.
Which other solutions did I evaluate?
I have never used any alternatives to Radware Cloud WAF Service. In my previous company and currently at our company, it has been Radware Cloud WAF Service.
What other advice do I have?
The source blocking feature is not utilized here as we use a different solution for source blocking. My colleague handles the Bot Manager aspects. Everyone here has different tasks, roles, and responsibilities, and we get assigned to specific incidents.
I rate Radware Cloud WAF Service nine out of ten.
Has improved real-time threat detection and simplified traffic analysis across multiple applications
What is our primary use case?
My use cases for Radware Cloud WAF Service in my current organization, where I serve as a Cyber Security expert and SOC analyst, involve deeply investigating live network traffic from both inside and outside our organization to improve security through real-time threat monitoring and live data analysis. For example, when a new application was set up in the Adani Group, which is a very big organization, we received significant traffic that day; we used Radware Cloud WAF Service to check the indicators and investigate accordingly, based on the rules we had set. This not only helps during predefined activities but also during unexpected high traffic instances, allowing us to enhance security effectively.
What is most valuable?
While there are many features of Radware Cloud WAF Service that I appreciate, one standout feature is the integration of seven applications of Adani for analysis, which provides a separate dashboard to monitor various domains effortlessly.
The user experience is designed to be straightforward, allowing easy preferences and interactions. Radware Cloud WAF Service effectively handles zero-day attacks by rapidly identifying vulnerabilities before they can affect our organization, which enhances our proactive measures through collaboration with various teams, such as the VA team, to address vulnerabilities and apply necessary patches.
What needs improvement?
Although I don't consider it to have significant downsides, I believe the UI could be improved to be more user-friendly, especially for new joiners in SOC who might struggle to understand the traffic based on numerical data. For instance, a tree chart feature available in other platforms, such as CrowdStrike, could simplify the understanding of traffic flow and save time on analysis.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for approximately 1.5 years, as I joined the Adani Group three months ago after working at N10 TechnoSoft, which involved development and cyber security.
What do I think about the stability of the solution?
I have not experienced any significant downtime or crashing with Radware Cloud WAF Service, although I have noticed occasional issues with logging in through SSO that cause redirects to a 404 page, which I resolve by restarting my browser.
What do I think about the scalability of the solution?
I find the scalability of Radware Cloud WAF Service to be very good and would rate it a 9 or a 9.5 on a scale of 1 to 10.
How are customer service and support?
I have contacted the technical support and customer support multiple times due to the need for clarification on functionality in our 24/7 SOC environment, where understanding various features is crucial for analysis. They have been responsive and helpful, reaching out within a day or two. If I were to score the support on a scale from 1 to 10, I would give it an 8.5. I would round that score up to a 9.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment of Radware Cloud WAF Service was easy; however, it required some time to understand fully. I estimate it took around two months to fully deploy Radware Cloud WAF Service for the first time, based on what I've heard from colleagues, as I recently joined the company where Radware Cloud WAF Service has been in use for more than three to four years.
What's my experience with pricing, setup cost, and licensing?
Regarding current pricing, it is managed by our higher authorities, but I believe the price is reasonable for our organization. If we expand our services in the future, the current pricing doesn't pose an issue for us, especially as it opens opportunities for profitability based on the services we utilize from Radware Cloud WAF Service.
Which other solutions did I evaluate?
While I haven't used direct alternatives to Radware Cloud WAF Service, I can mention that we consider CSPM in our cloud segment. The company is exploring the possibility of providing services to other companies, signaling future growth and deeper integration of Radware Cloud WAF Service.
What other advice do I have?
In terms of API usage, I focus on using the bot management and API security functionalities of Radware Cloud WAF Service, which protect against automated threats such as DDoS attacks created by bots.
Overall, I would rate Radware Cloud WAF Service an 8.8; while there are strong features present, there is room for improvement, particularly concerning end-user analytics, which would justify a higher score.
Radware - One stop solution for WAF
Has significantly improved threat visibility and reduced false positives through intelligent bot detection and real-time analysis
What is our primary use case?
My use case for Radware Cloud WAF Service is mainly for WAF bot protection.
What is most valuable?
The best features of Radware Cloud WAF Service that I prefer most include the bot protection. Its deployment was very smooth and flexible when I started deploying it. The reporting and visibility feature of the Bot Manager are noteworthy, as the dashboard gives clear insight into the traffic, activity, and block threats. The AI threat intelligence feature is quite impressive.
In terms of blocking unknown threats and attacks, I assess Radware Cloud WAF Service as quite impressive; if I have to rate it out of 10, I would rate it eight and a half.
The automated analytics for looking at events with Radware Cloud WAF Service is generally fine, and whenever we use it, it gives almost perfect results.
In API protection with Radware Cloud WAF Service, we have multiple applications that we are using currently, and whenever there is any threat related to an API, it helps us provide detailed insight. Additionally, whenever there is unusual API traffic, it helps us monitor and detect threats.
What needs improvement?
In Radware Cloud WAF Service, the areas that have room for improvement include customization and personalized integration, as we faced multiple issues with those aspects during our deployment.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for approximately one and a half years.
What do I think about the stability of the solution?
Regarding stability, I can say that in the last one and a half years, I haven't seen any downtime, so I would rate that 10 out of 10.
What do I think about the scalability of the solution?
In terms of scalability, it's also a 10 out of 10 because we are using Radware Cloud WAF Service for more than 60,000 employees in our organization, and it works perfectly fine.
How are customer service and support?
I would rate Radware support nine out of 10; it's perfectly fine, and an engineer is available all the time, resolving our issues in a timely manner.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
When I compare Radware Cloud WAF Service with other WAF software, we used to use different WAF software before Radware, and now we've switched to Radware. There are multiple benefits, such as cost, efficiency, threat intelligence, and multiple features, so Radware is quite impressive compared to other WAF solutions.
What's my experience with pricing, setup cost, and licensing?
Regarding overhead costs, we used a different solution before Radware, so it's not quite expensive, but it is moderately expensive. Radware Cloud WAF Service does the job in a cost-effective way as.
Which other solutions did I evaluate?
The other WAF solutions I am referring to include Akamai and F5.
What other advice do I have?
In terms of false positives, Radware Cloud WAF Service helps reduce them to around 30 to 35%. Cloud WAF saves me time; before, there were multiple false positive incidents that used to create too much workload for an analyst, and now we can say it has improved efficiency by 10 to 12% on average.
Radware Cloud WAF Service integrates seamlessly with other applications and solutions, although we faced difficulties with two or three vendors; other than that, it was perfectly smooth.
Radware Cloud WAF Service's ability to protect against zero-day attacks is very good; the threat intelligence feature is excellent in the WAF. It helps us protect against zero-day threats significantly, and whenever a zero-day occurs, it notifies us as early as possible, helping us get it resolved.
I find the combination of negative and behavioral-based positive security models highly important, and if I were to rate it on a scale of 10, I would rate it as eight and a half to nine.
We have Radware Cloud WAF Service deployed on firewalls, such as an MSPL entire network, and even though we use the Source Blocking feature, I cannot say we fully utilize it. With the Source Blocking feature, the automated, proactive, and holistic approach based on cross-module correlation is working perfectly fine.
I use Radware Bot Manager. With Bot Manager, I haven't discovered anything new in terms of incoming bot traffic, but it helps us identify bot traffic and real traffic. Radware helps to distinguish between the two, improving things such as blocking the IPs or managing the traffic, ensuring that genuine service is available and easily accessible for real users.
Radware Bot Manager helps with compliance significantly; for instance, whenever there's a web application, it identifies bot traffic and genuine traffic, allowing us to block the bot traffic so that services for genuine users are more available. In Radware Cloud WAF Service, the real-time BLA detection and mitigation help us in a very effective way by saving time and making the solution efficient.
I use the Web DDoS for HTTP L7, and it helps us very much; it helps distinguish between malicious and genuine traffic. Approximately, there are multiple users for Cloud WAF; our organization contains a total of 60,000 to 65,000 employees who use the WAF, along with customer-facing sites that also use the service. The solution requires maintenance according to our policy, such as managing the blocking list and related tasks.
I would definitely recommend Radware Cloud WAF Service to other users because it features multiple tools that help reduce workload and manage bot traffic. Additionally, it assists in mitigating zero-day threats and notifying us further, providing numerous solutions to customer problems. Overall, I would rate the solution from 1 to 10 as eight and a half to nine.
Blocking unauthorized IPs and geo-locations has become faster and more effective with stronger protection against zero-day attacks
What is our primary use case?
My use case for Radware Cloud WAF Service is to block all IPs and geo-locations that are not required in the organization.
What is most valuable?
Blocking based on geolocation is very helpful.
The automated analytics for analyzing events are beneficial for automation and make it easier for analysts working in the SOC. It is useful for analytical purposes as it helps us understand how we can perform various activities that Radware Cloud WAF Service belongs to.
Radware Cloud WAF Service has reduced our false positive rate by more than 50%. Regarding the blocking feature, Radware Cloud WAF Service is one of the best tools as we can easily block and reduce our alerts through IP blocking. We utilize CDN services with Radware Cloud WAF Service, and although it was initially challenging to understand, once we grasped it, it became easy for us.
I am using web DDoS protection with Radware Cloud WAF Service, and it is a very good product for protecting our businesses. The WAF protection is excellent and does not require any improvements as it is already working effectively and is executable. Radware Cloud WAF Service is really good for protecting against zero-day attacks as it protects our organization and businesses effectively. For patching purposes, once a zero-day attack has been exploited, we can block some geo-locations to prevent other attackers from targeting us.
Compared to other Cloud WAFs, Radware Cloud WAF Service is one of the best since it blocks for protection purposes within 15 to 20 minutes when we raise an incident, while it takes longer for others to implement geo-fencing and related protections.
What needs improvement?
The area that can improve with Radware Cloud WAF Service is the speed at which they block geo-fencing and IP for P1 cases, which currently takes about an hour. If they could reduce that to ten to 15 minutes, it would be easier for us.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for one and a half years.
What do I think about the stability of the solution?
I rate the stability of Radware Cloud WAF Service as ten out of ten, as there are no glitches, and when they occasionally happen, they notify us, making it easier than other services.
What do I think about the scalability of the solution?
More than 500 users are using Radware Cloud WAF Service.
How are customer service and support?
I would rate the technical support as ten out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
I find the solution easy to deploy.
What's my experience with pricing, setup cost, and licensing?
The pricing is moderate, making it affordable for any business and not overly costly.
What other advice do I have?
I definitely recommend Radware Cloud WAF Service products to other users as it is comparatively good, not very costly, and the service they provide is among the best.
I rate this solution ten out of ten.