Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs NetScaler comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
75
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (13th)
Barracuda Web Application F...
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
44
Ranking in other categories
Web Application Firewall (WAF) (17th)
NetScaler
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
107
Ranking in other categories
Application Delivery Controllers (ADC) (1st), Network Management Applications (5th), Web Application Firewall (WAF) (12th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
UmeshKumar2 - PeerSpot reviewer
If an attack is continuous, it can block it temporarily for two to three minutes
I would rate the solution a nine out of ten. I use both Barracuda WAF and F5 but Barracuda is easy to use. F5 offers more control at another level. You can control your ship like a user. In Barracuda WAF, you can add or modify anything only with the help of support. Most of the features in Barracuda WAF are available in GUI mode. In the second version of F5, you can write iRules and apply them easily on the device. If you need something in the parameter level, you need to scan and then enable and disable the metacharacter for that particular parameter. There are some profilings available in Barracuda but they are not like F5. F5 has more general and applicable heuristics than Barracuda. However, there are good things about Barracuda too. If an attack is coming continuously, you can ask the device to block it temporarily for two to three minutes. F5 has not provided us with an option to block certain IPs for some time. Barracuda can help you block someone if the source is from a different IP. You can apply the rule to the device and block it for whatsoever time you want. The solution will unblock the IP after the prescribed time as well. This feature is not available in F5. F5 handles the implementation of single parameters and environmental parameters for financial applications easily. The profiling aspect is slower in Barracuda. Barracuda is easy for new people since everything that you need to implement the solution is available through the UI. You need little guidance for the solution. Anyone with knowledge of the HTTP header and signatures can use it very easily. It is more like Cisco in networking.
DEMİRHAN ÇAVUŞOĞLU - PeerSpot reviewer
A tool for centralized management including inventory and sales tracking
Citrix ADM has the ability to implement policies to tighten security. For instance, you can restrict access to your network from outsiders or lack necessary security measures such as antivirus programs. Additionally, there's the Delivery Controller, which allows for comprehensive monitoring and management tasks such as remote restarts, maintenance, and registration. Another essential component is the Director, which provides detailed insights into sessions, including identifying session failures, connection issues, user lockouts, etc. It presents a list of problems to address, enabling you to click on them and resolve them efficiently.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a fast and secure DNS."
"Cloudflare DNS is widely used, and it's good for websites. If we use Cloudflare DNS and update one record, it updates in their office instantly."
"It is a fast and secure DNS."
"The solution automatically detects and responds to certain types of traffic based on geolocation."
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"Cloudflare consolidates various capabilities into one product, streamlining processes."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"It allows us to scale out to multiple phase servers."
"It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment."
"This product gives us visibility into what is going on in two servers, including connections and sessions, real-time alerts, very good reporting, and KPIs. It makes managing security of a critical server very easy, with a friendly GUI."
"The most valuable feature is the rule set."
"The customer service and support from Barracuda have been excellent."
"Its recommendation about the probabilities on the website is great. It also has free probability managers for the website, which is really helpful. The protection engine, signature-based protection behavior, and analysis features are also great. It also has an ATP module for sandbox scanning and behavior analysis for file uploads."
"The most valuable features of Barracuda Web Application Firewall include advanced bot protection, DDoS protection, and addressing the top ten vulnerabilities."
"The solution offers multiple security features. There are machine learning features and great URL encryption. It also offers multi-protocol support against DDoS attacks."
"The solution is very stable."
"The MAS integration for HDX Insight has provided teams with significant visibility into network performance of the user's connection."
"Provides resiliency for applications that reside on servers, as well as connectivity to remote applications."
"My clients use it for load balancing."
"Compared to other solutions, Citrix ADC is much more robust in terms of the native integration to cloud platforms. It is far more robust from an operational point of view as well."
"Global load balancing between data centers."
"The most valuable features are the VDA Delivery, Gateway Fort, and the load balancing."
"Citrix Director has been great. It gives us one pane of glass to be able to monitor what's going on with the user sessions as well as to keep on top of the virtual desktops, any servers that may be offline or behaving suspiciously, or any troublesome spots like disconnections. We also use Citrix Studio for maintaining the actual servers that are hosting these applications. We use it for delivery groups in case we need to modify delivery groups in regards to which groups have access to which applications. It has been very helpful."
 

Cons

"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"Integration involving API with other products could be more user-friendly."
"Although I think it's quite good, it doesn't provide me with all the features I would expect to have if I were using Imperva."
"The solution could use more analytics on the backend to give us more insights into everything. More reports would be helpful."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"The solution could work at being less expensive. It costs a lot to use it."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Cloudflare doesn't have a reverse lookup. We can only do a DNS lookup to get the IP address from the hostname. It doesn't work if you want to look up the hostname from an IPA address."
"The incident reporting needs to be improved."
"There are false positives that I am receiving when compared to other WAFs."
"The policy updates could be improved."
"We encountered a few glitches while implementing API security features into the product."
"There are issues when upgrading firewalls and we experience different issues across customers."
"Barracuda Web Application Firewall's load balancing feature could be improved."
"The solution needs to leverage some additional features to a broader scale of software-defined networks."
"This product could easily progress to be among the industry leaders. I think they need to improve enterprise level automation. It integrates with a small number of vulnerability scanners, so report results should be imported manually; same for SIEM integration."
"The WAF component needs to be simplified so that it is easier to use."
"Technical support sometimes takes a little longer because of the multilevel ticket priority."
"It does not have a sandbox cloud service and antivirus. It should have on-prem or cloud sandboxing and antivirus."
"Citrix ADC is a complex product, and it takes time to understand these things. But the documentation is poor, and the deployment is difficult. Integration could also be better because what I find is that you cannot easily integrate the panel in the second sector. What I have found is that in the last index, there is a limitation when getting validated. Technical support could also be better."
"The technical support has room for improvement."
"Citrix ADC can improve if it provides a more user-friendly interface and clear working protocols. Citrix is not working with classic RFC, it is working with Citrix RFC, which is not common in the world. If engineers of Citrix can provide us with more information on working with the classic IP networks it would be a benefit."
"The technical support could be better. Whenever I contacted support, I rarely got the solution that we needed. And most of the time, I finished fixing the problem by looking on the internet or by finding documents about the problem on Google."
"The tool needs to add a feature where we can access the network policy access manager."
 

Pricing and Cost Advice

"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"A free version of the solution is available."
"We are using the free tier of the solution."
"The tool is a premium product, so it is very expensive."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"The price of the solution is expensive."
"The product's pricing is cheap."
"The product is expensive."
"They only offer a yearly licensing plan."
"They have competitive pricing."
"In my opinion, the product is fairly priced."
"Barracuda costs us $8,000 per year. Barracuda costs $20,000 for a full subscription, when you try to protect multi-site infrastructure, in different geographical zones and for different data centers. If you have only one site, Barracuda will be cheaper."
"The product is inexpensive."
"The solution is based on a licensing model and might be $360 for the hybrid version."
"The price is reasonable, more so than other products."
"Citrix NetScaler VPX is not the cheapest solution out there, but you get what you pay for."
"You get the value for your money. There aren't any hidden fees."
"Citrix NetScaler's pricing is slightly above average but not overly expensive. I would consider F5 BIG IP to be the most expensive, Citrix NetScaler to be the second most expensive, and then Kemp Load Balancer to be the third."
"F5 BIG-IP is much more expensive than Citrix ADC. For example, If we choose two platforms, Citrix ADC, 3000 version, and we choose F5, F4200 version. F5 BIG-IP has connections, timers, and throughput similar to Citrix ADC, but the price is very expensive."
"It is true that it is a bit pricey compared to newer technologies coming to the market. For example, A10 is a load balancer that does everything that Citrix can and it does a lot more than what NetScaler does when it comes to the security space, and their prices are so cheap. Every box comes with its own license and support built into it. When you compare that with NetScaler, you have to buy licenses separately, you have to buy a support agreement that is going to be separate. A small NetScaler, even if it is a VPX which is a virtual server, could cost you close to $150,000 to $200,000 dollars. So the pricing is really high."
"We get value for money. Its price is fair. I don't think it is overpriced."
"Citrix ADM costs us approximately $5000 per month."
"This product is more expensive than some of the competitors."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
15%
Computer Software Company
14%
Comms Service Provider
9%
Financial Services Firm
9%
Computer Software Company
20%
Financial Services Firm
10%
Government
7%
Educational Organization
6%
Computer Software Company
15%
Educational Organization
12%
Financial Services Firm
11%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs...
What is your primary use case for Barracuda Web Application Firewall?
Our primary use case was to track the traffic on websites or webshops to identify potential malicious actors, such as...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
The pricing for Barracuda is quite high compared to other OEMs. Each transaction requires my purchase team to negotia...
What do you like most about Citrix ADC?
The most valuable feature for us is the application firewalling in Citrix NetScaler, ensuring only valid traffic ente...
What is your experience regarding pricing and costs for Citrix ADC?
After deployment, Citrix Netscaler shifted to a subscription-based license scheme for support, which is slightly more...
What needs improvement with Citrix ADC?
Citrix NetScaler is a robust product, but mastering it requires significant learning and training due to its complexi...
 

Also Known As

Cloudflare DNS
No data available
Citrix ADC, Citrix NetScaler VPX, NetScaler Console, NetScaler Web Application Firewall
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
ABB Schweiz, Aer Lingus, AIDS Healthcare Foundation, Amnet Technology Solutions, Aramex International, Ascenty, Atos, Autodesk
Find out what your peers are saying about Barracuda Web Application Firewall vs. NetScaler and other solutions. Updated: April 2025.
851,604 professionals have used our research since 2012.