We used Barracuda Web Application Firewall to protect the banking system. There were cyber drills where we had to find some logs, share those logs, and identify the attacks.
Manager at Inspira Enterprise
Easy to set up and use, stable, and has no scalability issues, but its attack identification capability and technical support need to be improved
Pros and Cons
- "What I like most about Barracuda Web Application Firewall is its availability. I also like that it's an easy-to-use solution."
- "An area for improvement in Barracuda Web Application Firewall is attack identification. Other banks identified attacks and tracked logs that the solution wasn't able to identify because of its ready-made rules pre-deployed by the vendor. My organization raised this issue with the technical support team. Another area to improve in Barracuda Web Application Firewall is its service desk. The team resorted to stonewalling because they couldn't accept that a feature was missing in the solution, and it was only after a lot of drilling down that the service desk team accepted that, and would be adding that feature in the future. My organization had to submit a report to the Reserve Bank of India with information on the logs identified and the attacks that happened, and that there was a failure on the part of the Barracuda Web Application Firewall. The Reserve Bank of India conducts a tri-monthly cyber risk audit in all Indian banks. Even smaller banks identified and caught attacks that my organization wasn't able to do, so I was looking into other solutions that competitor banks could be using because Barracuda Web Application Firewall failed to identify some of the attacks."
What is our primary use case?
What is most valuable?
What I like most about Barracuda Web Application Firewall is its availability. I also like that it's an easy-to-use solution.
What needs improvement?
An area for improvement in Barracuda Web Application Firewall is attack identification. Other banks identified attacks and tracked logs that the solution wasn't able to identify because of its ready-made rules pre-deployed by the vendor. My organization raised this issue with the technical support team.
Another area to improve in Barracuda Web Application Firewall is its service desk. The team resorted to stonewalling because they couldn't accept that a feature was missing in the solution, and it was only after a lot of drilling down that the service desk team accepted that, and would be adding that feature in the future.
My organization had to submit a report to the Reserve Bank of India with information on the logs identified and the attacks that happened, and that there was a failure on the part of the Barracuda Web Application Firewall. The Reserve Bank of India conducts a tri-monthly cyber risk audit in all Indian banks. Even smaller banks identified and caught attacks that my organization wasn't able to do, so I was looking into other solutions that competitor banks could be using because Barracuda Web Application Firewall failed to identify some of the attacks.
For how long have I used the solution?
I've used Barracuda Web Application Firewall for six months in the past year.
Buyer's Guide
Barracuda Web Application Firewall
December 2024
Learn what your peers think about Barracuda Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
Barracuda Web Application Firewall is a stable product.
What do I think about the scalability of the solution?
Barracuda Web Application Firewall is a scalable product. Scaling it up isn't an issue.
How are customer service and support?
I wasn't happy with the technical support for Barracuda Web Application Firewall, particularly because of the intentional stonewalling by the team. The support team should accept if a threat wasn't caught by the solution. Support should accept that there's a problem in Barracuda Web Application Firewall and improve or fix that problem. My organization had to do a lot of drilling down before the technical support team accepted that the solution was lacking, and that was frustrating.
My rating for the Barracuda Web Application Firewall technical support team is a two out of five.
How was the initial setup?
Barracuda Web Application Firewall was easy to set up. It's a physical appliance, and I only needed one engineer to do the setup. My support engineer set the product up remotely, and it wasn't difficult.
I don't remember how long the deployment took for Barracuda Web Application Firewall because it was done by one of my engineers, but the solution was easy to deploy.
What about the implementation team?
Barracuda Web Application Firewall was implemented by a support engineer from my organization.
What other advice do I have?
I don't remember which version of Barracuda Web Application Firewall I used, but it was the latest at the time.
My organization has a few people using Barracuda Web Application Firewall. Only four or five people use the product.
What I would tell people to do before using Barracuda Web Application Firewall is to first have a POC with different vendors and solutions and even use one or more open source firewalls and WAFs before making a decision. You have to first do a lot of research before installing Barracuda Web Application Firewall because even some open source WAFs can identify some attacks that Barracuda isn't able to identify.
My rating for Barracuda Web Application Firewall is six out of ten.
I'm a product user and not a reseller or partner of Barracuda Web Application Firewall.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Information Security Officer at a insurance company with 10,001+ employees
Reliable and stable with a straightforward setup
Pros and Cons
- "The solution has been quite stable. It's reliable."
- "The solution needs to leverage some additional features to a broader scale of software-defined networks."
What is our primary use case?
Typically these web application firewalls act as an additional layer primarily for traffic. The web application firewalls are more of a safeguard if a company still has legacy technologies, for which they don't have the patches. It's basically used for the protection and security of web applications.
What is most valuable?
The solution has been quite stable. It's reliable.
The initial setup is mostly straightforward.
What needs improvement?
I wouldn't say that the solution is flexible. The technology is moving towards having the firewall, which is distributed to each workload, rather than having a static firewall pertaining to a particular application or a cohort of applications. There are other solutions that are much more flexible in this regard. VMware, for example, gives good flexibility in this regard.
The solution needs to leverage some additional features to a broader scale of software-defined networks.
Given the distributed computing and decentralized architecture with people working in hybrid modules, there'll be lesser and lesser control. People would like to have, for example, edge computing, et cetera, which is going to be the future for computing. Hence every organization would like to scale the design to the extent where they would like to have their defenses also go along with their workloads.
If, for an SDN, I need to go to VMware, and, for WAF, I need to go to Barracuda, or different other firewalls, the company is losing market share. They need to increase flexibility, agility, scaling, et cetera, as that is going to be the new normal, maybe in the next two to five years.
For how long have I used the solution?
We've been using the solution for close to two years at this point.
What do I think about the stability of the solution?
The solution is quite stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
I'm not sure about the scalability. I would need to explore it more. The most scalable products are likely VMware's NSX, as it is a company that's bit on cloud migration cloud transformation strategies. They'd like to ensure their workloads are safe and secure. I don't see this in traditional RAFs or even firewalls.
It's difficult to found how many users are on the solution at this time as we use multiple web application firewalls on different applications. It is not every application however, there would be certain applications that would have a WAF. Likely, it's around 10,000 users across applications.
We do plan to continue to use the solution into the future.
How are customer service and technical support?
We haven't really had to engage with technical support. I can't speak to how helpful or responsive they are in general.
Which solution did I use previously and why did I switch?
We did use a different solution before switching to Barracuda. Typically, we run a POC first before moving onto anything new, which is what happened in this case.
How was the initial setup?
The initial setup is pretty straightforward. However, it does help to have some depth of knowledge with the solution.
I cannot recall the exact amount of time the deployment took.
While I don't have dedicated staff on the solution to handle maintenance, I have about six people on my team that can cover whatever needs to be done when something arises.
What's my experience with pricing, setup cost, and licensing?
Licensing is something the procurement team takes care of. I don't have any insights in terms of the licensing agreement or costs that may be involved.
What other advice do I have?
We are customers and end-users.
Typically, we keep updating our infrastructure, and therefore, we are likely using the latest version of the solution, however, I do not have the version number on-hand.
I would recommend the solution to other organizations.
Overall, we've been quite satisfied with the capabilities of this product. I would rate it at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Barracuda Web Application Firewall
December 2024
Learn what your peers think about Barracuda Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
Manager Information Technology at a tech services company with 11-50 employees
A solution which offers simplicity and is scalable, stable, easy to install and offers good technical support
Pros and Cons
- "Our customers value the solution's simplicity."
- "It would be better if their updates would be released annually."
What is most valuable?
Our customers value the solution's simplicity.
What needs improvement?
Occasionally, upon installation of the Energize Updates, the plans will go off track, something which necessitates us calling up their support team for another update.
The frequency of the release of the updates is also an issue. In the production environment, Firmware cannot be frequently updated. It would be better if their updates would be released annually.
For how long have I used the solution?
We have been dealing with Barracuda Web Application Firewall for more than four years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and technical support?
Our experience with technical support has been very positive.
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
While I would have to check on the price of the solution, I feel it to be okay and it matches the market price.
Which other solutions did I evaluate?
F5, Imperva and RedBear are the main competitors of Barracuda in our area.
I do not know if they possess certain features which Barracuda Web Application Firewall lacks. I would have to check.
What other advice do I have?
I would recommend the solution to someone looking for a new web application firewall.
I rate Barracuda Web Application Firewall as an eight out of ten. I do not give the product a higher rating because there are other solutions in Sri Lanka of which the vendors are aware through the Gartner Reports. I believe the solution is not not counted amongst the Gartner leader Quadrant.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Pre-Sales Engineer at eCam Solution Co., Ltd
Policy updates could be improved; I like the dashboard
Pros and Cons
- "Has a good dashboard."
- "The policy updates could be improved."
What is our primary use case?
Our primary use case is for banking compliance. I'm a presales engineer.
What is most valuable?
I like the dashboard.
What needs improvement?
The policy updates could be improved.
For how long have I used the solution?
I've been using this product for four years.
What do I think about the scalability of the solution?
Scalability is good but could be improved.
How was the initial setup?
The initial setup isn't too complex, we have a master plan when we implement it for our customers and deployment usually takes around three months. We have several people on our team involved with maintenance; usually, our customers also have maintenance staff.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
IT Manager at Toshiba Tec Poland
Simple to manage with a good client VPN and content filtering
Pros and Cons
- "The most valuable features are the client VPN and content filtering."
- "The incident reporting needs to be improved."
What is most valuable?
The most valuable features are the client VPN and content filtering.
This solution is simple to manage.
The interface and the dashboards are ok.
What needs improvement?
The incident reporting needs to be improved.
The local technical support in Poland is not very reliable.
For how long have I used the solution?
I have been using the Barracuda Web Application Firewall for three years.
What do I think about the stability of the solution?
This solution is very stable. It is great.
What do I think about the scalability of the solution?
I have only the single web application firewall running on-premises, so I cannot comment on scalability other than to say that I haven't had any problems.
We have 18 people who are being protected by this firewall and we do have plans to increase to approximately 100.
How are customer service and technical support?
I have been in contact with technical support and while I feel that they are not very reliable here in Poland, they are good enough and I am satisfied with them. The escalation was okay and the troubleshooting was also okay.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is okay.
What other advice do I have?
My advice to anybody who is implementing this solution is to find a good partner to assist with the implementation.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
We run it with no downtime, because it has good support
Pros and Cons
- "We run it with no downtime, because it has good support."
- "It is not stable nor mature."
What is our primary use case?
We use it for mail protection.
How has it helped my organization?
It has helped the organizational function because we do not have an application hosted product.
What is most valuable?
It mainly provides good support, and it is a good web application for us.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It is not stable nor mature, though it is not a problem for us.
What do I think about the scalability of the solution?
We have had scalability issues. However, since we do not have that many applications, it is not an issue for us.
How are customer service and technical support?
Technical support is very good.
Which solution did I use previously and why did I switch?
We did not previously use another solution.
How was the initial setup?
The initial setup was very straightforward.
What's my experience with pricing, setup cost, and licensing?
The pricing is less compared to other web applications, which is important to us.
Which other solutions did I evaluate?
We compared the solution to Imperva because of the support. Support is important to us.
What other advice do I have?
Just do it. We run it with no downtime, because it has good support.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Director of Systems Infrastructure at a tech vendor
Allows us to scale out to multiple phase servers
Pros and Cons
- "It allows us to scale out to multiple phase servers."
- "If you know nothing about networks, then you can't set it up."
What is our primary use case?
We use it for low balancing phase servers.
How has it helped my organization?
It allows us to scale out to multiple phase servers.
It is a great product. We are very pleased with it.
What is most valuable?
It works exactly by design. It works very well.
What do I think about the stability of the solution?
There are no stability issues.
What do I think about the scalability of the solution?
There are no scalability issues.
How is customer service and technical support?
Their technical support is great.
How was the initial setup?
If you are a networking guy, the initial setup is straightforward. If you know nothing about networks, then you can't set it up.
What's my experience with pricing, setup cost, and licensing?
They have competitive pricing.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Consultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Strong updating features but the tech support is weak
Pros and Cons
- "The updating and signature features are my primary use case for the solution. These features are beneficial to my organization."
- "I would suggest that someone implementing this product is knowledgeable in the IT field, and with the network needs. It is complex."
What is our primary use case?
The updating and signature features are my primary use case for the solution. These features are beneficial to my organization.
What needs improvement?
I would like this solution to be more detective of the needs of the organization.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
I encountered issues with the stability of the product.
What do I think about the scalability of the solution?
I encountered issues with scalability.
How is customer service and technical support?
I would rate the level of tech support a six out of ten.
How was the initial setup?
I would suggest that someone implementing this product is knowledgeable in the IT field and with the network needs. It is complex.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Barracuda Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Imperva Web Application Firewall
Radware Alteon
Reblaze - part of Link11
Buyer's Guide
Download our free Barracuda Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Imperva WAF vs. Barracuda: Which One is Better?
- Which is better, Barracuda Web Application Firewall or F5 Advanced WAF?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?