AWS Web Application Firewall - AWS WAF

Protect your web applications from common exploits.

AWS Web Application Firewall - AWS WAF

Protect your web applications from common exploits

With AWS WAF, you can create security rules that control bot traffic and block common attack patterns such as SQL injection or cross-site scripting (XSS).

Be one of our happy customers using AWS WAF

AWS Web Application Firewall protection service

AWS WAF Features

Protect your web applications with flexible security rules, real-time traffic visibility, managed protection, and centralized control.

Attack Protection

Inspect web requests and block malicious traffic using customizable rules designed to reduce common attacks with minimal impact on application performance.

Traffic Visibility

Gain near real-time insight into web traffic to support alerts, security automation, analytics, troubleshooting, and audit requirements.

Managed Rules

Use automatically updated protections for common threats, including OWASP risks, so your team can focus on building and improving applications.

Central Control

Manage and reuse security rules across multiple applications through AWS Firewall Manager for consistent protection.

Traffic Filtering

Filter requests using IP addresses, HTTP headers, request bodies, custom URIs, and other conditions tailored to your security requirements.

Account Security

Monitor application login pages and help prevent unauthorized account access that relies on compromised usernames and passwords.

AWS Web Application Firewall logo
AWS WAF architecture diagram showing web traffic filtering and application protection

Gartner AWS WAF Ratings

Explore independent customer reviews and ratings for AWS WAF on Gartner.