Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs Imperva Web Application Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Barracuda Web Application F...
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
42
Ranking in other categories
Web Application Firewall (WAF) (17th)
Imperva Web Application Fir...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
Web Application Firewall (WAF) (6th)
 

Q&A Highlights

it_user566739 - PeerSpot reviewer
Dec 07, 2016
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Carlo Bertini - PeerSpot reviewer
Provides strong issue discovery capabilities; enhance the security parameters of web applications and suitable for medium to large enterprises
The Barracuda support depends. Sometimes, they solve the issue promptly, but normally, they are not so fast and are not entirely focused on the problem. For example, sometimes I write many requests on the tickets, asking for one, two, three, or four steps and asking for one to three resolutions. Often, they respond with only one or two. So, I need to push again and again. In other cases, I ask questions and get positive feedback immediately, depending on who the technician is. Barracuda has engineers in the USA, UK, and other countries, so it depends on the technician's location and expertise. So, I am not completely satisfied, but sometimes it is okay, and sometimes it is not okay. So, depending on the region and depending on the person who actually receives these tickets, the technical support could be more knowledgeable. So they may need some training or education for the entire staff to respond immediately without any delays. Often, it happens that they respond because they need to, not because they understand the technology I'm using. So they respond just because it's required by the service level agreement, which specifies a response time within four hours. But this is just a response, not a resolution of the case. Sometimes, the response is within the agreed time, but the solution takes much longer.
Abdullah Jin - PeerSpot reviewer
Offers bot protection and DDoS Protection and protects public-facing portals
Support is one thing I wish Imperva could improve. They follow the phone model and keep rotating you from one customer service person to another. The layer one support isn't very clear about the workings of the product. My feedback is primarily about Imperva Cloud, not on-premise. On-premise is a whole new story. Support is the issue for Imperva Cloud. It's also a bit pricey. It's a premium service and very expensive. The licensing model is not very straightforward. Every feature is priced separately, and to enjoy maximum protection, you'll have to spend a lot of money. The licensing model is a bit complex, and each feature is very pricey. For example, API security and web application protection are two separate license packages.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The web application firewall brought us good security and a view of the accesses/blocks of the entire domain and subdomain that were accessed both by region (country) and IPs."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"The most valuable feature of Cloudflare DNS is security."
"It is easier to configure and develop documentation to see how we have configured firewalls."
"The most valuable feature of Cloudflare DNS is its global reach and it is always evolving."
"It's very user-friendly."
"The solution offers the flexibility to control configuration rules."
"The installation is straightforward."
"It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment."
"It allows us to scale out to multiple phase servers."
"The product's advanced bot and threat protection capabilities are valuable."
"The solution is user-friendly and easy to set up."
"Data leak prevention is very important and ensures protection against attacks."
"The most valuable features are the client VPN and content filtering."
"One of the strongest points is its robust issue discovery capabilities. Barracuda invests significant efforts in identifying and resolving issues. They have multiple products that work in tandem to perform these checks, which is beneficial because it automates security updates. This is the primary reason I recommend it to my customers."
"The dynamic profiling of websites is the solution's most valuable feature. The security is also good."
"The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis."
"Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva."
"Very scalable and very stable firewall for web applications, with a good interface in its cloud version. Mitigation is its most valuable feature. The technical support for this product is also good."
"If you are using the appliance as opposed to the virtual deployment, it can stand as the network layer-two and provide real transparency."
"Imperva WAF's strongest features are the detection of web application threats and vulnerabilities in the source code."
"Compared to other web application firewalls in the market, Imperva does things in the most accurate way."
"Protection is the best solution since it has profile functionality."
 

Cons

"For the free and Pro plans, Cloudflare could use a simple bot to provide information to users. This would improve support, especially for less advanced users who utilize the free components."
"Latencies are always a problem."
"Cloudflare should add more documentation and pricing to the cloud version."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"Technical support is lacking."
"Cloudflare's console should be made more user-friendly."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"If you know nothing about networks, then you can't set it up."
"The solution could use more reports."
"I would like to see better controlling of the traffic."
"There are issues when upgrading firewalls and we experience different issues across customers."
"An area for improvement in Barracuda Web Application Firewall is attack identification. Other banks identified attacks and tracked logs that the solution wasn't able to identify because of its ready-made rules pre-deployed by the vendor. My organization raised this issue with the technical support team. Another area to improve in Barracuda Web Application Firewall is its service desk. The team resorted to stonewalling because they couldn't accept that a feature was missing in the solution, and it was only after a lot of drilling down that the service desk team accepted that, and would be adding that feature in the future. My organization had to submit a report to the Reserve Bank of India with information on the logs identified and the attacks that happened, and that there was a failure on the part of the Barracuda Web Application Firewall. The Reserve Bank of India conducts a tri-monthly cyber risk audit in all Indian banks. Even smaller banks identified and caught attacks that my organization wasn't able to do, so I was looking into other solutions that competitor banks could be using because Barracuda Web Application Firewall failed to identify some of the attacks."
"The usability of the interface could be improved."
"One of Barracuda's limitations is its user interface. The GUI for configuration is not intuitive and has remained largely unchanged for the past 10 to 12 years."
"The platform's pricing needs improvement."
"The tool's UI is complicated. It would be best to have a more accessible UI dashboard to make the job easier."
"The product's customization capabilities are a bit problematic, requiring support cases for backend modifications."
"It would be nice to have more security control over mobile applications so I would suggest adding more mobile security features. It would also be beneficial to see improvements in regards to interface bandwidth performance, CPU time, and RAM size. Learning capability of the device is quite weak."
"It's a complicated tool to keep."
"There's always room for improvement. Occasionally, there might be false-positive alerts."
"Sometimes our web application firewall will slow down."
"In the past, I have bugs on the WAF. I've contacted Imperva about them. Future releases should be less buggy."
"The solution works for particular zones but isn't always the best solution for all zones."
 

Pricing and Cost Advice

"The product's pricing is cheap."
"The tool is a premium product, so it is very expensive."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"The price of the solution is expensive."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The price is reasonable."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"While I would have to check on the price of the solution, I feel it to be okay and it matches the market price."
"Our licensing fees are paid annually and the cost is between €600 and €800 (approximately $665.00 to $885.00 USD)."
"For small companies, the price is very expensive because the WAF is an enterprise-level application, not intended for smaller businesses. In my opinion, the price is right for enterprise-level use."
"The price is reasonable, more so than other products."
"The product is inexpensive."
"Barracuda costs us $8,000 per year. Barracuda costs $20,000 for a full subscription, when you try to protect multi-site infrastructure, in different geographical zones and for different data centers. If you have only one site, Barracuda will be cheaper."
"They only offer a yearly licensing plan."
"The solution is based on a licensing model and might be $360 for the hybrid version."
"Imperva Web Application Firewall is expensive."
"The tool is expensive."
"Imperva Web Application Firewall's pricing is expensive."
"It's an excellent product, but it can be very costly."
"The pricing is somewhat expensive. It is actually a huge investment when compared to other countries."
"The cost of this solution depends on the platform."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"There are a couple of different licensing models."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Answers from the Community

it_user566739 - PeerSpot reviewer
Dec 8, 2016
Dec 8, 2016
To prevent OWASP TOP 10 (SQL Injection, XSS, XSFR...etc) attacks, stop L7 DDoS like SlowLoris and HeavyURL, protect against web fraud, phishing and endpoint malware (Dridex) on endpoint machines outside administrative control, secure application API's, the option to deploy as a managed service in the cloud and available on premises, use DAST integration for policy building with Qualys, Cenzic, ...
2 out of 13 answers
it_user307584 - PeerSpot reviewer
Dec 7, 2016
Today i would say Barracuda is the better WAF based on that Imperva Dev slowed down over the last two years and the customers give bad feedback on the support, but there is a newer generation of WAF´s in the market that is better than Imperva and Barracuda, both in performance and price, PT application firewall, the only visionary in the GMQ
Dec 7, 2016
Neither. F5 Networks Sent from my iPhone
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
7%
Computer Software Company
20%
Financial Services Firm
10%
Manufacturing Company
8%
Educational Organization
7%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
7%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs...
What is your primary use case for Barracuda Web Application Firewall?
I'm using Barracuda as a web application firewall for any application. It is too smart and user-friendly, making it e...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
On a scale, pricing is nine out of ten. It's a reasonable price for this product.
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you hav...
DDoS solutions: Any other solutions to consider aside from Radware DefensePro and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot ...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Barracuda Web Application Firewall vs. Imperva Web Application Firewall and other solutions. Updated: January 2025.
831,265 professionals have used our research since 2012.