Try our new research platform with insights from 80,000+ expert users

Barracuda WAF-as-a-Service vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (13th)
Barracuda WAF-as-a-Service
Average Rating
7.2
Reviews Sentiment
7.4
Number of Reviews
5
Ranking in other categories
Web Application Firewall (WAF) (33rd)
Fortinet FortiWeb
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
96
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Carlos Alam Hernandez Baruch - PeerSpot reviewer
Fast and secure deployments simplify operations for government and fintech clients
It is a fast and secure DNS. It is very easy to deploy, and my customers are happy with this tool. Additionally, the CDN performance in Mexico is excellent, providing fast service and tools. It offers reliability during high-traffic periods, ensuring no impact on the environment. It helps my clients avoid using on-premise boxes, simplifying operations as they only use the prices on Cloudflare.
Hadar Eshel - PeerSpot reviewer
Easy to install platform with valuable policy management features
We use the product for securing email systems, protecting websites, and safeguarding web-based applications and portals One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strategy. Additionally, it could operate in a local data center.…
OcheEluma - PeerSpot reviewer
Enhanced security with comprehensive traffic inspection and some downtime automation needs
One area that needs improvement is the handling of SaaS downtime. When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well. Although measures like built-in redundancy and manual switching between data centers exist, there is room for improvement in making these transitions automatic without impacting the customer. Automating the migration without manual intervention would significantly enhance user experience during downtime. Additionally, being able to read non-flagged traffic for operational purposes could also be an area to improve.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is easier to configure and develop documentation to see how we have configured firewalls."
"Centralized, full-featured DNS."
"The most valuable feature is its usability."
"Easier http to https redirect using page rules"
"The most valuable feature of Cloudflare DNS is its global reach and it is always evolving."
"Generally, I am satisfied with this product."
"It's very user-friendly."
"The most valuable features of the solution are performance and security."
"The product's bot protection feature is valuable for our company."
"The most valuable features of the solution are it is plug and play, has automated policies, a simple configuration, and is easy to create rules."
"It provides an ease of policy management."
"The solution can be used for threat prevention or as a cloud-to-cloud backup system"
"I like its ability to identify known attacks, including DDOS attacks. It's valuable because software must be able to stop known attacks. Application attacks are evolving all the time. When it comes to software-as-a-service, we need to have software that knows about all the latest attacks. It should also protect against major unknown attacks."
"The most valuable feature in this solution is the ability to disseminate between the user entering some wrong value to the field, and a suspicious actor trying to exploit some known vulnerability."
"The most valuable features in Fortinet FortiWeb are sandboxing and threat prevention."
"L-7 protection makes possible to protect legacy/not up-to-date servers/applications without changing the application code."
"What we like about Fortinet FortiWeb is it has all the features. We use all of them, so we have to turn on all the options."
"High-performance and detection engines, provide a high rate of exposure of web attacks."
"The most valuable feature is the attack signature and machine learning."
"The ability to configure multiple policies for different requirements is a strong feature of Fortinet FortiWeb."
"The product has a very user-friendly dashboard."
 

Cons

"The tool needs to improve caching of servers. The product needs to include PFX certificate as well."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"Even if I wanted to, I wouldn't be able to buy Cloudflare in my country."
"I believe they currently have this feature, but there will most likely be integration with APIs so we can control some features through API."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"There should be a specific price list for enterprise-level customers."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Although I think it's quite good, it doesn't provide me with all the features I would expect to have if I were using Imperva."
"The solution can improve by bundling Security Operation Center (SOC) with the WAF-as-a-Service, it would provide a lot more value to customers."
"One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strategy."
"The stability of the product is an area of concern where improvements are required."
"It's a very specific solution that is only requested for a customer's web code or their global IT policy."
"We found it a bit slow when accessing it through the web browser. The URL also exposed the user name and the hashed password. When I log into my Barracuda WAF user portal, I could see the username and the hashed password on the URL itself. So, it is not very secure, and it is important to take that off."
"No solution is 100% secure and the security could always be worked on."
"Integration and learning about attacks. I would improve these areas by making FortiWeb integrate with other network technologies and feedback from multiple platforms."
"A better load balancer is needed when multiple servers are used for the same website."
"Fortinet FortiWeb is not scalable. You'll need more budget to change the hardware."
"The initial setup depends on familiarity with the product. It's manageable with the right expertise."
"FortiWeb needs to have support for the newest technology being used in web applications."
"Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company."
"FortiGate could be improved on the security end because we've had some incidents with the customer. Otherwise, there is no problem."
 

Pricing and Cost Advice

"The cost primarily depends on the size of the organization."
"We are using the free tier of the solution."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"The price of the solution is expensive."
"There are no additional costs beyond the standard licensing fees."
"We are using the free version."
"We don't have any issues with the price."
"The product is expensive but it offers flexible pricing. It could be affordable."
"It's very difficult for me to give an estimate of the cost. All I know is that we sell the box itself as a service."
"I rate the product's price a five on a scale of one to ten, where one is low, and ten is high. There are no additional costs to be paid apart from the standard licensing fees attached to the solution."
"​The pricing is reasonable."
"FortiWeb can be purchased in VM mode for a lower price and the same features."
"If one is very cheap and ten is very expensive, I rate the product price as three or four."
"The solution gives us the best price to performance ratio."
"All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500."
"It is an expensive suite and it is an expensive solution, but it is a manageable one for an enterprise."
"The price is competitive."
"There's only one payment for the duration of the license. On a scale from one to five, I would rate pricing at four. I have not encountered any additional costs on my projects involving Fortinet FortiWeb."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
865,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Comms Service Provider
11%
Financial Services Firm
9%
Manufacturing Company
7%
Government
15%
Computer Software Company
14%
Media Company
7%
Comms Service Provider
7%
Computer Software Company
13%
Financial Services Firm
10%
Government
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What needs improvement with Barracuda WAF-as-a-Service?
One significant area for improvement in Barracuda WAF-as-a-Service lies in its market positioning and pricing strateg...
What is your primary use case for Barracuda WAF-as-a-Service?
We use the product for securing email systems, protecting websites, and safeguarding web-based applications and portals.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing for Fortinet FortiWeb varies with different models having different prices. It depends on the requirement...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in Fortinet FortiWeb. The team was only from FortiGate itself. They are making new firm...
 

Also Known As

Cloudflare DNS
Barracuda WAF as a Service
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Salvation Army
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Barracuda WAF-as-a-Service vs. Fortinet FortiWeb and other solutions. Updated: July 2025.
865,295 professionals have used our research since 2012.