Try our new research platform with insights from 80,000+ expert users

Barracuda WAF-as-a-Service vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Barracuda WAF-as-a-Service
Average Rating
7.2
Number of Reviews
5
Ranking in other categories
Web Application Firewall (WAF) (31st)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
93
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Hadar Eshel - PeerSpot reviewer
Easy to install platform with valuable policy management features
We use the product for securing email systems, protecting websites, and safeguarding web-based applications and portals One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strategy. Additionally, it could operate in a local data center.…
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cloudflare allows us to self-host services such as Rocket.Chat and Node-RED, in high-availability mode, thanks to round robin DNS which allows us to share one hostname between our two locations."
"The solution is stable, and the DNS servers are simple to use."
"Cloudflare DNS is widely used, and it's good for websites. If we use Cloudflare DNS and update one record, it updates in their office instantly."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"The solution is very good at mitigating threats."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"The technical support is good."
"The solution offers the flexibility to control configuration rules."
"I like its ability to identify known attacks, including DDOS attacks. It's valuable because software must be able to stop known attacks. Application attacks are evolving all the time. When it comes to software-as-a-service, we need to have software that knows about all the latest attacks. It should also protect against major unknown attacks."
"The most valuable features of the solution are it is plug and play, has automated policies, a simple configuration, and is easy to create rules."
"The solution can be used for threat prevention or as a cloud-to-cloud backup system"
"It provides an ease of policy management."
"The product's bot protection feature is valuable for our company."
"When it comes to blocking unknown threats and attacks, I would give it the highest score possible. We first started using AWS and its Web Application Firewalls. That was okay, but it was quite a manual process to keep it up to date, whereas Fortinet is always up to date, and the default rules or the modules that you can turn on are very easy to use."
"The reason I recommend this product is because it guarantees that your network will be safe if it is set up properly and you fully utilize most of the functions."
"It's the extra security that is the most valuable feature. You have insight into your traffic. There are some great insights into what utilities hackers are trying to exploit. It blocks a lot of stuff from the internet."
"The product's initial setup phase was straightforward, and since our company didn't have any problems with it, we didn't encounter many problems with the tool."
"You have the ability to control everything from one single dashboard."
"FortiWeb provides the level of security we need at an excellent price point. It's easy to deploy and operationally efficient."
"I like FortiWeb's usability and ease of configuration. It's simple to configure rules and exceptions inside the attack log. We block everything by default. If something isn't working, we ask the system admin to adjust the template and add exceptions."
"The policies and the filtering are the most valuable features, especially traffic, URL, and application filtering. The solution is excellent at detecting vulnerabilities."
 

Cons

"It would be good if Cloudflare could have more servers for better traffic routing or an increase in the traffic routed. This is what I'd like to improve in Cloudflare."
"Although I think it's quite good, it doesn't provide me with all the features I would expect to have if I were using Imperva."
"The timing aspect can lead to it being considered overpriced. This is a particular concern we have with Cloudflare, as they may struggle with accurately detecting the client."
"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"There might be helpful if there was some web application firewall feature."
"Cloudflare's console should be made more user-friendly."
"Latencies are always a problem."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"The stability of the product is an area of concern where improvements are required."
"We found it a bit slow when accessing it through the web browser. The URL also exposed the user name and the hashed password. When I log into my Barracuda WAF user portal, I could see the username and the hashed password on the URL itself. So, it is not very secure, and it is important to take that off."
"The solution can improve by bundling Security Operation Center (SOC) with the WAF-as-a-Service, it would provide a lot more value to customers."
"One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strategy."
"It's a very specific solution that is only requested for a customer's web code or their global IT policy."
"We have had problems with deployments where we've had to contact technical support to resolve them."
"The initial setup process could be improved."
"When we look at the incident reports in the dashboard, they are available for a maximum duration of 24 hours. They should provide more time for the analysis and increase the duration of the availability of these reports. Currently, it gives the options for 5 minutes, 1 hour, and 24 hours. It would be excellent if there are more options for a longer time period. It may be configurable, but I don't know how to do it."
"We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."
"They can introduce a scaled-down version for the SMB market. It would be very competitive in the environment."
"Its threat intelligence capabilities may not be as advanced as some competitors."
"I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted."
"Centralized management of multiple devices, and GUI improvement, could reduce the learning curve."
 

Pricing and Cost Advice

"A free version of the solution is available."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"We are using the free tier of the solution."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"I give the price a five out of ten."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"The product is expensive but it offers flexible pricing. It could be affordable."
"It's very difficult for me to give an estimate of the cost. All I know is that we sell the box itself as a service."
"I rate the product's price a five on a scale of one to ten, where one is low, and ten is high. There are no additional costs to be paid apart from the standard licensing fees attached to the solution."
"It should be somewhere about 36,000 Euros. That's the cost for three years. It's moderately priced."
"It is fine now. We had to earlier negotiate the price."
"The pricing is pretty good. We do pass a lot of traffic through our API servers. Something like 100 gigs of web traffic is a fair amount for reduced JSON API calls, but the cost is $50. For that peace of mind, we have thousands and thousands of customers that are protected by that $50, so it's a no-brainer."
"The solution gives us the best price to performance ratio."
"The costs are standard. We pay around $1,600 yearly."
"The maintenance fee for this product could be improved."
"FortiWeb can be purchased in VM mode for a lower price and the same features."
"The solution is cheaper compared with other solutions. It has a yearly license."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
824,067 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
7%
Financial Services Firm
7%
Computer Software Company
21%
Comms Service Provider
11%
Financial Services Firm
9%
Manufacturing Company
9%
Educational Organization
43%
Computer Software Company
9%
Financial Services Firm
8%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What needs improvement with Barracuda WAF-as-a-Service?
One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strateg...
What is your primary use case for Barracuda WAF-as-a-Service?
We use the product for securing email systems, protecting websites, and safeguarding web-based applications and portals.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing of Fortinet FortiWeb is affordable and competitive.
What needs improvement with Fortinet FortiWeb?
I see no room for improvement at the moment.
 

Also Known As

Cloudflare DNS
Barracuda WAF as a Service
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Salvation Army
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Barracuda WAF-as-a-Service vs. Fortinet FortiWeb and other solutions. Updated: December 2024.
824,067 professionals have used our research since 2012.