Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
72
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Barracuda Web Application F...
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
43
Ranking in other categories
Web Application Firewall (WAF) (17th)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
94
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Carlo Bertini - PeerSpot reviewer
Provides strong issue discovery capabilities; enhance the security parameters of web applications and suitable for medium to large enterprises
The Barracuda support depends. Sometimes, they solve the issue promptly, but normally, they are not so fast and are not entirely focused on the problem. For example, sometimes I write many requests on the tickets, asking for one, two, three, or four steps and asking for one to three resolutions. Often, they respond with only one or two. So, I need to push again and again. In other cases, I ask questions and get positive feedback immediately, depending on who the technician is. Barracuda has engineers in the USA, UK, and other countries, so it depends on the technician's location and expertise. So, I am not completely satisfied, but sometimes it is okay, and sometimes it is not okay. So, depending on the region and depending on the person who actually receives these tickets, the technical support could be more knowledgeable. So they may need some training or education for the entire staff to respond immediately without any delays. Often, it happens that they respond because they need to, not because they understand the technology I'm using. So they respond just because it's required by the service level agreement, which specifies a response time within four hours. But this is just a response, not a resolution of the case. Sometimes, the response is within the agreed time, but the solution takes much longer.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like Cloudflare's application gateway and DDoS protection."
"From what I've seen so far, there are no negatives to report as of yet"
"The solution provides good load balancing and protection against DDoS attacks."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"Cloudflare is a security SaaS provider that provides security and protects us from any application layer attack."
"The solution is stable, and the DNS servers are simple to use."
"Smaller businesses have seen great ROI due to the low investment and strong performance."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"The stability of the solution is good. I don't think we've experienced bugs, crashes, or glitches."
"It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment."
"The solution's most valuable feature is that it actually protects our website, and it provides all the required security functions."
"The product's advanced bot and threat protection capabilities are valuable."
"The most valuable feature is the rule set."
"The initial setup is pretty straightforward, especially if you enlist assistance."
"Our customers value the solution's simplicity."
"It is stable and the performance is good."
"FortiWeb offers machine learning in the latest product. This fixed many problems. There are no false negatives."
"The GUI makes it easy to scale in terms of learning and utilization."
"I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks."
"FortiWeb provides the level of security we need at an excellent price point. It's easy to deploy and operationally efficient."
"Both the internal firewall management and the cloud can be managed by a single console."
"It can scale well."
"The solution is easy to configure and deploy."
"It's easy to use and allows us to integrate solutions together."
 

Cons

"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"There are some issues with the CDN services."
"The solution could use more analytics on the backend to give us more insights into everything. More reports would be helpful."
"Even if I wanted to, I wouldn't be able to buy Cloudflare in my country."
"The timing aspect can lead to it being considered overpriced. This is a particular concern we have with Cloudflare, as they may struggle with accurately detecting the client."
"We are a product integrator and reseller, and we would like to have a better partner relationship, similar to a channel sales relationship. Sometimes we are on our own or get diverted by Cloudflare because they have direct sales, which competes with us and makes it difficult to build a relationship with this company since we want to be an MSP or a managed service provider for the solution."
"It should have easier documentation for the configuration. It's very technical and people who aren't technical should also be able to do the configuration."
"I have to go to an individual obligation, make changes, and come out, and go to the next obligation and make the same changes. There is no grouping option."
"The documentation is lacking. It's not like what you'd get if you were using Juniper or Cisco. They need to expand on it and make it more useful."
"There are issues when upgrading firewalls and we experience different issues across customers."
"I would like to see an improved capacity to store logs so that they will be available for a longer time."
"The solution could use more reports."
"It would be better if their updates would be released annually."
"If you know nothing about networks, then you can't set it up."
"The solution needs to leverage some additional features to a broader scale of software-defined networks."
"Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company."
"We use Kubernetes, so I would like to have a plugin to configure FortiWeb Cloud automatically using Kubernetes Ingress. That would reduce the complexity of setting up an Ingress object in Kubernetes. Some competing solutions help you configure Ingress and Kubernetes automatically."
"The documentation for the machine learning could be better."
"Describing security rules should be improved. It's tricky to define new feature tools when you want to describe an attack pattern and want to block it."
"Fortinet's technical support is pretty slow."
"It would also be helpful if they could introduce easier reporting. It's good to have those reports that go to C-level management, and Fortinet does provide some graphs, but if they went into some more detail, that would be great."
"The solution could have more customization."
"The memory use in each of the appliances is problematic."
 

Pricing and Cost Advice

"A free version of the solution is available."
"The cost primarily depends on the size of the organization."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"The price of the solution is expensive."
"In my opinion, the product is fairly priced."
"The price is reasonable, more so than other products."
"The price of the solution is a little expensive. There is a license for this solution and it can be purchased every one, two, or five years."
"The price of this solution is okay."
"The pricing is reasonable."
"For small companies, the price is very expensive because the WAF is an enterprise-level application, not intended for smaller businesses. In my opinion, the price is right for enterprise-level use."
"The Barracuda Web Application Firewall is quite expensive."
"The product is inexpensive."
"​The pricing is reasonable."
"There are no costs in addition to the standard licensing fees."
"The maintenance fee for this product could be improved."
"The solution is very inexpensive when compared to F5 Advanced WAF and Avi Networks but offers the same benefits."
"Cheaper than others."
"It should be somewhere about 36,000 Euros. That's the cost for three years. It's moderately priced."
"The price of Fortinet FortiWeb is expensive in our Ethiopian currency."
"The price of Fortinet FortiWeb depends from customer to customer because some customers are considering using other solutions, such as Imperva. The price of Fortinet FortiWeb sits well for the middle-sized customers that we deal with."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
8%
Computer Software Company
21%
Financial Services Firm
10%
Government
7%
Educational Organization
6%
Educational Organization
43%
Computer Software Company
8%
Financial Services Firm
7%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs...
What is your primary use case for Barracuda Web Application Firewall?
I'm using Barracuda as a web application firewall for any application. It is too smart and user-friendly, making it e...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
On a scale, pricing is nine out of ten. It's a reasonable price for this product.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
I would rate the licensing cost as seven out of ten, considering it good value for money. The price is affordable and...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in the portability on multi-cloud environments. Enhanced DDoS integration to make Forti...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Barracuda Web Application Firewall vs. Fortinet FortiWeb and other solutions. Updated: January 2025.
838,713 professionals have used our research since 2012.