Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs Imperva DDoS comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
72
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Barracuda Web Application F...
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
43
Ranking in other categories
Web Application Firewall (WAF) (17th)
Imperva DDoS
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (7th), Web Application Firewall (WAF) (19th), Distributed Denial-of-Service (DDoS) Protection (7th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Carlo Bertini - PeerSpot reviewer
Provides strong issue discovery capabilities; enhance the security parameters of web applications and suitable for medium to large enterprises
The Barracuda support depends. Sometimes, they solve the issue promptly, but normally, they are not so fast and are not entirely focused on the problem. For example, sometimes I write many requests on the tickets, asking for one, two, three, or four steps and asking for one to three resolutions. Often, they respond with only one or two. So, I need to push again and again. In other cases, I ask questions and get positive feedback immediately, depending on who the technician is. Barracuda has engineers in the USA, UK, and other countries, so it depends on the technician's location and expertise. So, I am not completely satisfied, but sometimes it is okay, and sometimes it is not okay. So, depending on the region and depending on the person who actually receives these tickets, the technical support could be more knowledgeable. So they may need some training or education for the entire staff to respond immediately without any delays. Often, it happens that they respond because they need to, not because they understand the technology I'm using. So they respond just because it's required by the service level agreement, which specifies a response time within four hours. But this is just a response, not a resolution of the case. Sometimes, the response is within the agreed time, but the solution takes much longer.
Syed Ubaid Ali Jafri - PeerSpot reviewer
I like the content monitoring feature which I haven't seen in other WAF solutions.
They could improve by minimizing false positive results. Although this occurs less with Imperva, we would like to see some further improvements. We have been using this product for last 1 years, it's result is very impressive. But due to the excessive load on the Web site where thousands of requests‎ are generated from legitimate users, however the request in which any sequential or specialised characters are requested would be directly blocked by impreva . Currently imperva blocks the special character request generated from the user, as I conduct a test where I am parsing the encoded html values of the same special characters to the input field, imperva bypasses these encoded values for example : ' i.e. %27 or / i.e %2F, the WAF bypasses these encoded characters. I hope that this device should have a capability to detect the pattern which is associated with Xss or Xsrf, rather then by not blocking the request which contains any special characters.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The technical support is good."
"Its most significant benefit to date is the speed with which it refreshes DNS records on the internet once you change it. If you are changing a website or registering a new record, it is very quick."
"Its ease of integration with Office 365 and the fact that it's a good product compared to what I had before"
"The solution offers the flexibility to control configuration rules."
"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"The most valuable feature of Cloudflare DNS is its global reach and it is always evolving."
"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"Setup of this solution is straightforward. It's a stable and scalable solution, with good performance and fast technical support."
"The solution offers multiple security features. There are machine learning features and great URL encryption. It also offers multi-protocol support against DDoS attacks."
"Has a good dashboard."
"The initial setup is pretty straightforward, especially if you enlist assistance."
"The volumetric DDoS defense is very good because I had a problem with a lot of volumetric DDoS attacks on my servers. After using Barracuda, those attacks have stopped and all the traffic is going smoothly to my servers and the system is working really well."
"The installation is straightforward."
"One of the strongest points is its robust issue discovery capabilities. Barracuda invests significant efforts in identifying and resolving issues. They have multiple products that work in tandem to perform these checks, which is beneficial because it automates security updates. This is the primary reason I recommend it to my customers."
"Parameter Protection is a valuable feature."
"Imperva DDoS is fairly stable, and its availability is quite high."
"Provides Anti-DDoS protection, as well as other protections like SQL injection, Cross-Site Scripting, and antiscanner. These types of protection are valuable to the business due to the daily attacks on our portals, and that often cannot be seen without a tool like this."
"The bot management features are very effective, as they help filter unwanted traffic using keywords."
"An improvement has been to our website: It increases the speed of our response, the capacity of the site, and optimizes the bandwidth.​"
"The complete solution is valuable for everything it delivers and the protection it offers."
"We have peace of mind that nobody will use malware on us or try to hack our website."
"The setup of Imperva DDoS was easy."
"Imperva Incapsula has many valuable features. One, it protects the top 10 OWAS vulnerability, the open web application software platform, this is standard. Secondly, it protects against broken authentication. As well, it has remote execution of code."
 

Cons

"Even if I wanted to, I wouldn't be able to buy Cloudflare in my country."
"One area of improvement is in the Access Rules. Hypothetically, if we wanted to block or challenge traffic outside of the United States, the only way to currently do that (as far as I know) is to enter every single country outside of the United States. That could be a labor intensive job. A solution could be to enable users to create a rule where traffic is only allowed within a certain country."
"Integration involving API with other products could be more user-friendly."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"Cloudflare's console should be made more user-friendly."
"If they improve on the placement of their data centers, it would be better. I'm living in a remote area. I would like to connect to them without any kind of lag."
"There should be a specific price list for enterprise-level customers."
"The usability of the interface could be improved."
"There are some vulnerabilities that are reported across the tools offered by Barracuda for some devices, which need to be taken care of from an improvement perspective."
"As most people are aware, the implementation is not easy."
"I have to go to an individual obligation, make changes, and come out, and go to the next obligation and make the same changes. There is no grouping option."
"We get false positives about phishing emails."
"The incident reporting needs to be improved."
"There are false positives that I am receiving when compared to other WAFs. The issues with false positives affect client transactions, leading to complaints about blocked transactions."
"They could improve their performance, support, and their upgrades. Their updates used to be good. Their improvements were right on the money but nowadays, the updates are minor."
"It would be better if we were able to manage and apply changes to multiple websites/web applications, and search WAF logs for multiple websites, via the Incapsula dashboard."
"It needs to be improved every time there are new attacks."
"We would like them to hire people in Sweden because it's quite hard when people are sitting in the UK or Belgium because some of the customers really want them to be local."
"It would be beneficial to include vulnerability management in the solution, similar to what they have for their on-premise solution."
"I miss being able to integrate the dashboard with other BI tools we are using. We have to export and import data to be able to present it, and doing so is a lot of work."
"Some maintenance must be performed by our IT team."
"We faced issues regarding compliance with client procedures. The client had strict compliance rules, and Imperva needed to be on a VM, while the client required containerization, causing a conflict. They went with Imperva for the on-premise version but shelved the cloud project due to too many blockers."
"Analytics in the area of risk need to be improved to supply more information to the users for creating better environments."
 

Pricing and Cost Advice

"We are using the free version."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"A free version of the solution is available."
"There are no additional costs beyond the standard licensing fees."
"The tool is a premium product, so it is very expensive."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"They have competitive pricing."
"The price of this solution is okay."
"The product is inexpensive."
"Barracuda costs us $8,000 per year. Barracuda costs $20,000 for a full subscription, when you try to protect multi-site infrastructure, in different geographical zones and for different data centers. If you have only one site, Barracuda will be cheaper."
"For small companies, the price is very expensive because the WAF is an enterprise-level application, not intended for smaller businesses. In my opinion, the price is right for enterprise-level use."
"The price is reasonable, more so than other products."
"They only offer a yearly licensing plan."
"While I would have to check on the price of the solution, I feel it to be okay and it matches the market price."
"The cost is somewhere around $10,000 a site. For every site, you pay individually. For every DNS entry, you have you pay."
"Varies depending on the needs of the customer."
"We are satisfied with the pricing."
"Pricing could be more competitive."
"The cost is on par with other solutions such as Cloudflare and Akamai."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a five out of ten."
"​Although the pricing can be a little high, it is worth the protection and security that it offers.​"
"The solution's price is high for small companies."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
8%
Computer Software Company
21%
Financial Services Firm
10%
Government
7%
Educational Organization
6%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs...
What is your primary use case for Barracuda Web Application Firewall?
I'm using Barracuda as a web application firewall for any application. It is too smart and user-friendly, making it e...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
On a scale, pricing is nine out of ten. It's a reasonable price for this product.
What do you like most about Imperva Incapsula?
We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping.
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing is rated a ten on a scale where ten is very expensive. The solution is only cloud-based and does not prov...
What needs improvement with Imperva DDoS?
Pricing can be improved, as it is quite expensive. Additionally, support response times for emails can sometimes be d...
 

Also Known As

Cloudflare DNS
No data available
Imperva Incapsula
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about Barracuda Web Application Firewall vs. Imperva DDoS and other solutions. Updated: January 2025.
838,713 professionals have used our research since 2012.