


Barracuda Web Application Firewall and Imperva Application Security Platform compete in the web application security space. Imperva seems to have the upper hand with its comprehensive cloud-based offerings, appealing to firms needing wide-ranging protection.
Features: Barracuda focuses on user-friendly features like bot traffic management and effective DDoS protection. Its simplicity in configuration, coupled with robust security capabilities, is highly valued. Imperva, on the other hand, emphasizes API security with features like threat detection and advanced bot protection. The cloud-based approach provides additional capabilities, offering extensive security suites.
Room for Improvement: Barracuda faces challenges with log storage and frequent false positives, demanding improved scalability and API security. Its console and interface could be more intuitive. Imperva's complex licensing and occasionally slow technical support are drawbacks. Enhancements in analytics depth, traffic visibility, and platform integration would benefit users, alongside refining interface and configuration options.
Ease of Deployment and Customer Service: Barracuda offers various deployment options, including on-premises and hybrid models, generally praised for customer support despite occasional regional inconsistencies. Imperva caters to enterprise-level networks with extensive cloud-oriented deployment. While both receive positive customer feedback, Barracuda's local support sometimes lacks regional expertise, whereas Imperva excels in cloud flexibility but may struggle with support efficiency.
Pricing and ROI: Barracuda offers competitive pricing with good ROI, particularly in reducing manual security efforts, though the cost may be steep for smaller businesses. Imperva is generally more expensive with complex licensing models, yet its comprehensive security capabilities may justify the price for companies needing broad protection and custom configurations.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
My development team is working on the latest language tools or applications, so until then, this web application firewall is essential in my network to protect my existing online assets or software.
We have seen a return on investment as the manual work for monitoring attacks and generating reports is reduced significantly, saving money.
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
I was able to save over seven million dollars last year as return on investment in the company.
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
I would rate customer support a solid ten, as they are consistently on top of every issue, addressing them without delays and providing excellent support twenty-four hours a day, seven days a week.
The customer service and support from Barracuda have been excellent.
The customer service and support are exceptional, and I would give them a ten out of ten.
I would rate the technical support of Imperva DDoS as ten.
They need to work faster on the response time because of issues of urgent replies.
Responsive support addressing urgent needs.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
The VMSS feature allows for easy upgrades or scaling of virtual editions.
I believe Barracuda Web Application Firewall is quite scalable, and I would rate it as an eight.
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
I have not even needed support after deployment, since it has remained stable.
It is easy to always scale to add more users.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
These result in clients complaining about blocked transactions on a daily basis.
Barracuda Web Application Firewall is stable in my experience.
It is also a stable product without much glitch or downtime.
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
Reducing false positives must be a priority.
The issues with false positives affect client transactions, leading to complaints about blocked transactions.
Tenable provides more comprehensive dark web scanning capabilities, which Barracuda could improve upon.
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
I requested a quote from Barracuda's UK team, which was half the price I was quoted in Pakistan.
The pricing for Barracuda is quite high compared to other OEMs.
They are competitive when compared to other vendors including F5 and Imperva, who tend to have higher prices.
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
the setup cost was high, with the hardware installation in the data center being particularly expensive.
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
The most valuable features of Barracuda Web Application Firewall include advanced bot protection, DDoS protection, and addressing the top ten vulnerabilities.
This process protects against attacks including SQL injection or cross-site scripting, where Barracuda Web Application Firewall will block any request that matches attack signatures.
The most valuable feature of Barracuda Web Application Firewall is managing bot traffic.
The API security feature is particularly valuable because most attackers do not try to come in from where it is expected.
If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address.
It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva.
| Product | Mindshare (%) |
|---|---|
| Imperva Application Security Platform | 7.7% |
| Cloudflare Web Application Firewall | 4.7% |
| Barracuda Web Application Firewall | 1.9% |
| Other | 85.7% |

| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 26 |
| Midsize Enterprise | 8 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 88 |
| Midsize Enterprise | 25 |
| Large Enterprise | 69 |
Cloudflare Web Application Firewall integrates DDoS protection, load balancing, and firewall capabilities. Its ease of use, configurability, and robust security measures make it a versatile choice for protecting web applications.
Cloudflare Web Application Firewall provides a comprehensive defense against threats with advanced reporting and robust security measures. It includes DNS integration, rate limiting, and extensive rule sets, all within a SaaS model that allows API configurability. Users value its caching, scalability, and pricing, although enhancements are needed in rate-limiting and third-party integration. Improvements in customer support, especially in India, real-time controls, and user documentation are also desired. Users seek a more intuitive dashboard, better log management, and improved alert systems, along with multitenancy capabilities and enhanced reporting.
What are the key features of Cloudflare Web Application Firewall?Cloudflare Web Application Firewall finds application in industries like banking and retail by acting as a comprehensive security gateway, managing authentication and authorization while protecting web applications from malicious Layer 7 traffic. It also implements load balancing, CDN, and zero-trust policies, supported by advanced reporting, analytics tools, and threat scoring to meet specific industry needs.
Barracuda Web Application Firewall combines advanced bot management, DDoS protection, and real-time threat detection for enhanced application security, making it a popular choice for safeguarding web environments.
Organizations rely on Barracuda Web Application Firewall for its robust features, including automatic security updates and comprehensive technical support. It offers a user-friendly interface, though improvements are needed in scalability and false positive reduction. It is widely used to enhance security against DDoS attacks, cross-site scripting, SQL injections, and malicious bots. Suitable for Azure environments, it manages legitimate traffic and ensures OWASP compliance across cloud and data centers.
What are the top features of Barracuda Web Application Firewall?Barracuda Web Application Firewall is implemented in industries like cloud and banking for its compliance capabilities and threat protection. It supports web applications through traffic filtering, server protection, and content inspection in hosting environments.
Imperva Application Security Platform delivers comprehensive and continuous web threat protection. Renowned for its ease of use, it shields web applications and databases from various cyber threats while integrating seamlessly with cloud and on-premises environments.
Imperva Application Security Platform protects web environments by offering advanced security measures against threats like DDoS attacks, SQL injections, and cross-site scripting. As a robust web application firewall, it provides extensive monitoring and bot management capabilities. The platform integrates content delivery networks for enhanced performance and scalability, while real-time traffic analysis ensures consistent protection. Despite its strengths, improvements can be made in policy management and customization options. Users seek better integration with third-party tools and more competitive pricing models. The inclusion of AI for enhanced analytics is also anticipated.
What are the key features of Imperva Application Security Platform?Imperva Application Security Platform is implemented in industries needing strong database and application protection. Companies use it to enforce geolocation restrictions and manage bots, benefiting sectors like finance and e-commerce where data security and threat monitoring are critical. Its ability to protect and ensure data accessibility makes it integral to business operations prioritizing cyber resilience.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.