Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs NGINX App Protect comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (13th)
Barracuda Web Application F...
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
44
Ranking in other categories
Web Application Firewall (WAF) (17th)
NGINX App Protect
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
24
Ranking in other categories
Web Application Firewall (WAF) (16th), Container Security (22nd), API Security (3rd)
 

Featured Reviews

Carlos Alam Hernandez Baruch - PeerSpot reviewer
Fast and secure deployments simplify operations for government and fintech clients
It is a fast and secure DNS. It is very easy to deploy, and my customers are happy with this tool. Additionally, the CDN performance in Mexico is excellent, providing fast service and tools. It offers reliability during high-traffic periods, ensuring no impact on the environment. It helps my clients avoid using on-premise boxes, simplifying operations as they only use the prices on Cloudflare.
Anne-Aimee Wollerich - PeerSpot reviewer
Managing bot traffic effectively enhances usability for non-technical users
Barracuda Web Application Firewall ( /products/barracuda-web-application-firewall-reviews ) lacks some of the more specified and structured features offered by solutions like Tenable. Although Tenable is more expensive and less easily deployable, its features are more deepened and chiseled, particularly for IT personnel. For example, Tenable provides more comprehensive dark web scanning capabilities, which Barracuda could improve upon.
Tomaz Sobczak - PeerSpot reviewer
Signature-based detection, DOS protection, and bot protection
NGINX App Protect is easier to automate and configure, or manage from an API. This is good for securing applications. However, it's not suitable for more complex tasks. NGINX App Protect positively impacted performance changes. There's a cache or it works like a proxy, so it can speed up applications. It can also offload some functions from servers, which NGINX can handle faster.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Centralized, full-featured DNS."
"Its most significant benefit to date is the speed with which it refreshes DNS records on the internet once you change it. If you are changing a website or registering a new record, it is very quick."
"The web application firewall brought us good security and a view of the accesses/blocks of the entire domain and subdomain that were accessed both by region (country) and IPs."
"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications."
"Easier http to https redirect using page rules"
"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"The solution is very good at mitigating threats."
"I find the solution very stable."
"The most valuable features of Barracuda Web Application Firewall include advanced bot protection, DDoS protection, and addressing the top ten vulnerabilities."
"It's very simple and predictable, because Barracuda provides a vision of the current state of your application. It gives you an understanding of what is happening on your site and any attempts against you at your source. This is the main value that Web Application Firewall provides our company. These aspects are also the main reason for this documentation process."
"The initial setup is pretty straightforward, especially if you enlist assistance."
"This product gives us visibility into what is going on in two servers, including connections and sessions, real-time alerts, very good reporting, and KPIs. It makes managing security of a critical server very easy, with a friendly GUI."
"The most valuable feature of this solution is the simplicity of configuration."
"The solution ensures layer seven is secure from attacks."
"Our customers value the solution's simplicity."
"Overall, I rate NGINX App Protect between eight and nine."
"I would say that the most valuable feature is the ability to operate in a DevOps environment and to be configured through API and pipeline by the developers themselves."
"The policies are flexible based on the technologies you use."
"NGINX App Protect is stable."
"NGINX App Protect's best features are auto-learning, which creates a profile of applications that are deployed, bot protection, and force protection, which lets you configure your brute force policy and alert for and prevent brute force attacks."
"The most valuable feature of NGINX App Protect is its open source."
"The most valuable feature is that I can establish different services from the firewall."
"The initial setup was simple and took three to four days."
 

Cons

"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"Although I think it's quite good, it doesn't provide me with all the features I would expect to have if I were using Imperva."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"The reporting aspect of the solution needs improvement. I don't find that it's very good. They could do some work on it to make it much better. It's not that the reporting isn't secure. It's just that I would prefer to store my reports for an extended period of time. Right now, that's not possible and I'd prefer it if that could change. I also would say that the reports themselves are expensive."
"There are false positives that I am receiving when compared to other WAFs. The issues with false positives affect client transactions, leading to complaints about blocked transactions."
"I would suggest that someone implementing this product is knowledgeable in the IT field, and with the network needs. It is complex."
"The documentation is lacking. It's not like what you'd get if you were using Juniper or Cisco. They need to expand on it and make it more useful."
"I have found F5 more stable than Barracuda Web Application Firewall. They should improve the stability."
"I would like to see better controlling of the traffic."
"If you know nothing about networks, then you can't set it up."
"The solution needs to leverage some additional features to a broader scale of software-defined networks."
"They could provide a better user interface."
"The configuration needs to be more flexible because it is difficult to do things that are outside of the ordinary."
"The integration of NGINX App Protect could improve."
"The dashboard could provide a more comprehensive view of the status of the connections."
"Areas for improvement would be if NGINX could scan for vulnerabilities and learn and update the signatures of DoS attacks."
"NGINX App Protect could improve security."
"The price of NGINX App Protect could improve."
"It would be better if it were easier to implement and if there was more information from F5 regarding hardware requirements and specifications to deploy the service, to avoid disruptions after implementation."
 

Pricing and Cost Advice

"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"That is one of the great features. I was able to access the majority of the features and services for free."
"We don't have any issues with the price."
"The cost primarily depends on the size of the organization."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"In my opinion, the product is fairly priced."
"The pricing is less compared to other web applications."
"The solution is based on a licensing model and might be $360 for the hybrid version."
"Our licensing fees are paid annually and the cost is between €600 and €800 (approximately $665.00 to $885.00 USD)."
"The price of this solution is okay."
"They have competitive pricing."
"The price is reasonable, more so than other products."
"While I would have to check on the price of the solution, I feel it to be okay and it matches the market price."
"Really understand the licensing model, because we underestimated that."
"The licensing fees for this solution are pretty expensive for what it does, but there is no alternative."
"The product's price is high."
"The solution's price is reasonable."
"The pricing is reasonable because NGINX operates on an instance basis."
"There are no additional fees."
"There are not any additional costs we had to pay to use NGINX App Protect."
"NGINX is not expensive."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
861,524 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Comms Service Provider
11%
Financial Services Firm
10%
Manufacturing Company
7%
Computer Software Company
19%
Financial Services Firm
10%
Educational Organization
7%
Manufacturing Company
6%
Computer Software Company
17%
Financial Services Firm
15%
Comms Service Provider
9%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs...
What is your primary use case for Barracuda Web Application Firewall?
Our primary use case was to track the traffic on websites or webshops to identify potential malicious actors, such as...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
The pricing for Barracuda is quite high compared to other OEMs. Each transaction requires my purchase team to negotia...
What is your experience regarding pricing and costs for NGINX App Protect?
I don't know the pricing yet because in my other project, I was not part of the buying side and I was just starting t...
What needs improvement with NGINX App Protect?
It would be better if it were easier to implement and if there was more information from F5 regarding hardware requir...
 

Also Known As

Cloudflare DNS
No data available
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Information Not Available
Find out what your peers are saying about Barracuda Web Application Firewall vs. NGINX App Protect and other solutions. Updated: July 2025.
861,524 professionals have used our research since 2012.