AWS WAF
WAF
You need to inspect and filter HTTP requests before they reach a supported application endpoint.
Reach for it when
- Applying managed or custom request rules to a supported resource.
- Limiting abusive request rates while reviewing false positives.
Do not reach for it when
- Restricting arbitrary TCP traffic in a subnet: use network controls.
- Replacing authentication and authorization inside an application.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| Security groups | Control network traffic to attached resources. |
| Shield | Evaluate the appropriate DDoS protection offering alongside request filtering. |
How you pay
- The model
- Web ACLs, rules, requests and selected managed features affect cost.
- The line item that surprises people
- Additional bot-control and marketplace features can have their own charges.
What trips people up
- Test rule behavior with suitable counting or observation before blocking legitimate users.
- Scope and supported attachment types matter; a WAF policy cannot be attached to every resource.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.