Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs Imperva Application Security Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Barracuda Web Application F...
Ranking in Web Application Firewall (WAF)
17th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
45
Ranking in other categories
No ranking in other categories
Imperva Application Securit...
Ranking in Web Application Firewall (WAF)
3rd
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
133
Ranking in other categories
CDN (2nd), Distributed Denial-of-Service (DDoS) Protection (4th), Bot Management (1st), API Security (2nd)
 

Mindshare comparison

As of February 2026, in the Web Application Firewall (WAF) category, the mindshare of Barracuda Web Application Firewall is 2.0%, up from 2.0% compared to the previous year. The mindshare of Imperva Application Security Platform is 7.8%, up from 7.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
Imperva Application Security Platform7.8%
Barracuda Web Application Firewall2.0%
Other90.2%
Web Application Firewall (WAF)
 

Q&A Highlights

it_user566739 - PeerSpot reviewer
Product Manager ( HP EG Enterprise ) at Ingram Micro
Dec 07, 2016
 

Featured Reviews

Shahzad Abid - PeerSpot reviewer
Director Information Technology at College of Physicians & Surgeons Pakistan
Has protected our legacy applications effectively but has required constant manual filtering due to false positives
I assess the effectiveness of the machine learning-driven threat detection in Barracuda Web Application Firewall as sometimes behaving abnormally, often showing me false positive attacks, so I have to fix these attacks from time to time. From a stability point of view, I would definitely rate Barracuda Web Application Firewall a seven out of ten. There is definitely some room for improvement; nothing is perfect in the world. I am not satisfied with the technical support from Barracuda. I am somewhat disappointed with the technical support that I have received so far. Whenever I generate a ticket for my problem, it goes to the Indian support team, and they all the time start with the most junior team member, consuming all my precious time. At the end, I have to close that ticket without any satisfactory solution. I have complained that they should shift my support to any other region because I don't need Indian support; they are simply pathetic and not up to mark. To improve Barracuda Web Application Firewall, customers should be given ongoing training opportunities regarding the product and its features. I am not familiar with many features that are available, only using those which are necessary for my applications. I believe Barracuda must provide clearer product information or training sessions to make it more user-friendly, as sometimes its interface can be rigid and lacking in helpful resources or user tutorials about its features. For it to get closer to a ten, I think advanced reporting is missing because, as I mentioned earlier, there are many false positive events being recorded. Often, when I analyze these attacks, they turn out to be genuine customers or users interacting with my product, but Barracuda tags them as attackers. Reducing false positives must be a priority.
reviewer1247523 - PeerSpot reviewer
Head of Sales Services Department at a comms service provider with 51-200 employees
Solution ensures website availability and proactive threat mitigation
Over the seven years, the most valuable features of Imperva DDoS that I have found are related to DDoS attacks, which are a group of attacks, and not all of them can be resolved on the endpoint level before the website. Using the web firewall before the website is a common use case to protect against malicious requests to the website. I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website. It allows me to granularly grant or deny access to certain parts of our website. This helps when we know our customers and the types of requests that can be sent from them, enabling us to block some malicious requests. Imperva DDoS has User Behavior Analytics and Threat Intelligence on its board, and this helps us to be protected proactively. Imperva DDoS connects to its database of threats, storing whole information about attacks all over the world in one simple engine. Everyone can use this feature, which can connect to this engine and get information about what is going on at the world level. That is the way to be protected at the company's level. The integration capabilities of Imperva DDoS are very easy and simple. We can run it in 2 hours.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's very simple and predictable, because Barracuda provides a vision of the current state of your application. It gives you an understanding of what is happening on your site and any attempts against you at your source. This is the main value that Web Application Firewall provides our company. These aspects are also the main reason for this documentation process."
"The product's advanced bot and threat protection capabilities are valuable."
"We only need one subscription to be protected against both active DDoS and offline DDoS attacks."
"If an attack is coming continuously, you can ask the device to block it temporarily for two to three minutes. F5 has not provided us with an option to block certain IPs for some time. Barracuda can help you block someone if the source is from a different IP. You can apply the rule to the device and block it for whatsoever time you want. The solution will unblock the IP after the prescribed time as well."
"The stability of the solution is good. I don't think we've experienced bugs, crashes, or glitches."
"Since implementing Barracuda, I sleep smoothly knowing I have protection."
"The volumetric DDoS defense is very good because I had a problem with a lot of volumetric DDoS attacks on my servers. After using Barracuda, those attacks have stopped and all the traffic is going smoothly to my servers and the system is working really well."
"The solution is user-friendly and easy to set up."
"We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping."
"Simplifies putting everything in code."
"Learning mode and custom policies are helpful features."
"DDoS protection and WAF are the most valuable features. It is easy to deploy a service. It is easy and quick to deploy to a new website."
"Its inline transferring mode is the most valuable because it is 100% transparent. When you change the IP, there is no change on the network side. If you can't and want to try to reach an IP, you can reach the server IP. There are many other advanced security features in it. The smallest appliances of Imperva can handle the highest traffic at a customer site. For example, a smaller appliance from Imperva can provide you the same security as an F5 product."
"Compared to other web application firewalls in the market, Imperva does things in the most accurate way."
"One good thing about Imperva Web Application Firewall is it can be on the cloud and also it can be on-premise."
"The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand."
 

Cons

"The usability of the interface could be improved."
"There are false positives that I am receiving when compared to other WAFs. The issues with false positives affect client transactions, leading to complaints about blocked transactions."
"We've had some blocks of the application and some false positives."
"One of Barracuda's limitations is its user interface. The GUI for configuration is not intuitive and has remained largely unchanged for the past 10 to 12 years."
"Barracuda Web Application Firewall's load balancing feature could be improved."
"There are some vulnerabilities that are reported across the tools offered by Barracuda for some devices, which need to be taken care of from an improvement perspective."
"I think the main area for improvement in this product is learning it, as can be seen when comparing it to the F5 web application firewall. F5 has a very powerful learning phase when you start using your web application firewall against your site. Barracuda has something like this, but not with the same functionality from my point of view."
"I would like to see better controlling of the traffic."
"The solution should integrate with something that looks at continuous security management."
"Analytics in the area of risk need to be improved to supply more information to the users for creating better environments."
"It would be helpful to have a "recommended deployment", or even a list of basic features that should either be used or turned on by default."
"It would be nice to have more security control over mobile applications so I would suggest adding more mobile security features. It would also be beneficial to see improvements in regards to interface bandwidth performance, CPU time, and RAM size. Learning capability of the device is quite weak."
"I would like the solution to improve its support response time."
"There is nothing specific where the application firewall is falling short."
"The user interface could be better."
"Certificate management could be improved."
 

Pricing and Cost Advice

"They only offer a yearly licensing plan."
"While I would have to check on the price of the solution, I feel it to be okay and it matches the market price."
"The pricing is less compared to other web applications."
"The price of this solution is okay."
"The product pricing was competitive for the value it offers regarding security features."
"Barracuda costs us $8,000 per year. Barracuda costs $20,000 for a full subscription, when you try to protect multi-site infrastructure, in different geographical zones and for different data centers. If you have only one site, Barracuda will be cheaper."
"The pricing is reasonable."
"The solution is based on a licensing model and might be $360 for the hybrid version."
"There is a license for this solution and we purchase the license annually with no additional fees."
"There are some licenses that you have to buy to use some features. Its price could be better. Price is always important because, at the end of the day, customers have a budget. If you can meet the budget, you can sell, and if you don't, you cannot sell."
"The license is on a yearly basis."
"It is expensive."
"Imperva’s pricing is a bit higher in the market since it offers a full-blown WAF."
"The cost is somewhere around $10,000 a site. For every site, you pay individually. For every DNS entry, you have you pay."
"The cost is on par with other solutions such as Cloudflare and Akamai."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
881,707 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Security Expert with 51-200 employees
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Answers from the Community

it_user566739 - PeerSpot reviewer
Product Manager ( HP EG Enterprise ) at Ingram Micro
Dec 8, 2016
Dec 8, 2016
To prevent OWASP TOP 10 (SQL Injection, XSS, XSFR...etc) attacks, stop L7 DDoS like SlowLoris and HeavyURL, protect against web fraud, phishing and endpoint malware (Dridex) on endpoint machines outside administrative control, secure application API's, the option to deploy as a managed service in the cloud and available on premises, use DAST integration for policy building with Qualys, Cenzic, ...
2 out of 13 answers
it_user307584 - PeerSpot reviewer
Sr Director of Sales Nordics, Russian Federation, Eurasia & CiS at a consultancy with 201-500 employees
Dec 7, 2016
Today i would say Barracuda is the better WAF based on that Imperva Dev slowed down over the last two years and the customers give bad feedback on the support, but there is a newer generation of WAF´s in the market that is better than Imperva and Barracuda, both in performance and price, PT application firewall, the only visionary in the GMQ
Dec 7, 2016
Neither. F5 Networks Sent from my iPhone
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
9%
Manufacturing Company
7%
University
6%
Financial Services Firm
12%
Computer Software Company
9%
Manufacturing Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business25
Midsize Enterprise8
Large Enterprise11
By reviewers
Company SizeCount
Small Business83
Midsize Enterprise25
Large Enterprise61
 

Questions from the Community

What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment.
What is your primary use case for Barracuda Web Application Firewall?
I am not using the API protection feature right now because I don't host any APIs through Barracuda Web Application Firewall. I use a second procedure for API, which is point-to-point VPN connectiv...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
At the time I was acquiring Barracuda Web Application Firewall, I found it costly compared to other products. To overcome that price factor, I excluded some features or subscriptions to align with ...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot management.
What do you like most about Imperva Incapsula?
We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping.
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provided. I would rate the pricing of Imperva DDoS as five, where one is very cheap a...
 

Also Known As

No data available
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about Barracuda Web Application Firewall vs. Imperva Application Security Platform and other solutions. Updated: February 2026.
881,707 professionals have used our research since 2012.