Try our new research platform with insights from 80,000+ expert users

Barracuda WAF-as-a-Service vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
74
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Barracuda WAF-as-a-Service
Average Rating
7.2
Reviews Sentiment
7.4
Number of Reviews
5
Ranking in other categories
Web Application Firewall (WAF) (31st)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
94
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Hadar Eshel - PeerSpot reviewer
Easy to install platform with valuable policy management features
We use the product for securing email systems, protecting websites, and safeguarding web-based applications and portals One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strategy. Additionally, it could operate in a local data center.…
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications."
"I rate its stability a ten out of ten."
"It is a fast and secure DNS."
"The most valuable feature of the solution is external DNS. It is also very secure. They have their own main server and once you configure it, the product takes care of everything. There are no issues in resolving IPs and low latency is also present."
"I like Cloudflare's application gateway and DDoS protection."
"The solution is stable, and the DNS servers are simple to use."
"Even when there is a high load on our servers, Cloudflare is able to cache the data and serve it to users, ensuring they can still access the website."
"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"The most valuable features of the solution are it is plug and play, has automated policies, a simple configuration, and is easy to create rules."
"I like its ability to identify known attacks, including DDOS attacks. It's valuable because software must be able to stop known attacks. Application attacks are evolving all the time. When it comes to software-as-a-service, we need to have software that knows about all the latest attacks. It should also protect against major unknown attacks."
"The solution can be used for threat prevention or as a cloud-to-cloud backup system"
"The product's bot protection feature is valuable for our company."
"It provides an ease of policy management."
"The most valuable feature is the attack signature and machine learning."
"We can block access using the IP address so no one can connect to our web server or website using the real IP."
"L-7 protection makes possible to protect legacy/not up-to-date servers/applications without changing the application code."
"The most valuable feature is the web application firewall (WAF)."
"High-performance and detection engines, provide a high rate of exposure of web attacks."
"You have the ability to control everything from one single dashboard."
"I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks."
"One main feature we are very happy about is file security and upload functionality."
 

Cons

"There might be helpful if there was some web application firewall feature."
"The pricing could be improved."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements."
"Cloudflare doesn't have a reverse lookup. We can only do a DNS lookup to get the IP address from the hostname. It doesn't work if you want to look up the hostname from an IPA address."
"There are some issues with the CDN services."
"It's a very specific solution that is only requested for a customer's web code or their global IT policy."
"One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strategy."
"We found it a bit slow when accessing it through the web browser. The URL also exposed the user name and the hashed password. When I log into my Barracuda WAF user portal, I could see the username and the hashed password on the URL itself. So, it is not very secure, and it is important to take that off."
"The solution can improve by bundling Security Operation Center (SOC) with the WAF-as-a-Service, it would provide a lot more value to customers."
"The stability of the product is an area of concern where improvements are required."
"We would like to know more about the integration with the hardware or security products, such as Gemalto, because we need to move to that point."
"In my experience, Fortinet FortiWeb could improve the intelligent features to acknowledge whether any threat or incident that's running happened. Then give us the ability to escalate it to layer 2 or layer 3 in the network operations."
"I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted."
"It may be better if it were easier to create roles."
"​Their support needs improvement."
"The initial setup in our data center was somewhat complex."
"When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well."
"We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."
 

Pricing and Cost Advice

"The product's pricing is cheap."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"We are using the free tier of the solution."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"The cost primarily depends on the size of the organization."
"We are using the free version."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"I rate the product's price a five on a scale of one to ten, where one is low, and ten is high. There are no additional costs to be paid apart from the standard licensing fees attached to the solution."
"The product is expensive but it offers flexible pricing. It could be affordable."
"It's very difficult for me to give an estimate of the cost. All I know is that we sell the box itself as a service."
"The license cost depends on the size of the box or the size of the solution. It can go from €200 Euros to a few hundred thousand Euros a year depending on your size."
"The license to use Fortinet FortiWeb is approximately $14,000."
"The pricing is in the middle. I would rate the pricing a five out of ten. It feels like a justified cost for the features."
"We are on an annual license for this solution and the price is approximately €100."
"Due to the situation in Iran with the sanctions, the price of this solution is very expensive."
"The price of Fortinet FortiWeb is reasonable. This is one of the key factors of why we use this solution."
"There are no costs in addition to the standard licensing fees."
"There's only one payment for the duration of the license. On a scale from one to five, I would rate pricing at four. I have not encountered any additional costs on my projects involving Fortinet FortiWeb."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
839,422 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
8%
Computer Software Company
21%
Financial Services Firm
10%
Comms Service Provider
10%
Non Profit
7%
Educational Organization
43%
Computer Software Company
8%
Financial Services Firm
7%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What needs improvement with Barracuda WAF-as-a-Service?
One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strateg...
What is your primary use case for Barracuda WAF-as-a-Service?
We use the product for securing email systems, protecting websites, and safeguarding web-based applications and portals.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
I would rate the licensing cost as seven out of ten, considering it good value for money. The price is affordable and...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in the portability on multi-cloud environments. Enhanced DDoS integration to make Forti...
 

Also Known As

Cloudflare DNS
Barracuda WAF as a Service
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Salvation Army
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Barracuda WAF-as-a-Service vs. Fortinet FortiWeb and other solutions. Updated: January 2025.
839,422 professionals have used our research since 2012.