Our main use case for Barracuda WAF-as-a-Service with clients is to secure their environments, especially for DDoS attacks and security vulnerabilities that we have found. We implement those solutions, and for smaller clients, we also suggest they adopt Barracuda WAF-as-a-Service. It is cheaper compared to other products in the market, but at the same time, it provides sufficient capabilities so clients can get started.
A recent situation where I recommended Barracuda WAF-as-a-Service to a client involved a security breach because their firewall was a different model from a different vendor and was not able to handle the breach or address the security concerns. We then recommended they adopt Barracuda WAF-as-a-Service. After implementing that solution, we resolved many attacks. Attacks continued to occur, but this time Barracuda WAF-as-a-Service was able to stop them, scan them, and prevent DDoS and DLP attacks. It was a good addition to that environment.
The best features Barracuda WAF-as-a-Service offers, in my experience, include bot protection, DDoS, and DLP. DDoS and bot API features are good. DLP does the job, but I would say it is not very good, though it will do the job for you.
When I mention DDoS protection and DLP, I can tell you that these features protect our clients from active DDoS attacks because most of our clients are public companies and well-known companies. Regardless of what kind of firewall or solution is implemented, people keep trying to break in. We see active, almost constant bot and DDoS attacks happening on those environments. Barracuda WAF-as-a-Service has never failed us so far. It is good, and we have not seen any clients complaining that it is not doing its job, failing, freezing, or hanging. It is doing its job.
Barracuda WAF-as-a-Service has significantly improved security in our organization and for our clients because without it, it was always a challenge to see what is happening in the environment, protect against bot attacks, protect against DDoS and DLP attacks, and ensure web protection. After adding this solution, there was a significant improvement in security for that environment.
I think Barracuda WAF-as-a-Service can still do better on the DLP side. The DLP side is a little weak, and their SaaS-based model which they provide in Azure and AWS is not very good. If you compare the high availability and fault tolerance of these with other products, I think those other products have advantages. If Barracuda WAF-as-a-Service can improve on availability, especially in public cloud infrastructures, that would be beneficial.
They also need to improve their support. Their support team is not very technical and helpful, and they need to ensure they provide the right person for the right support, especially when a ticket is open. Technically, when someone opens a ticket, they have already completed basic troubleshooting. Barracuda WAF-as-a-Service needs to hire more skilled engineers.
I have been using Barracuda WAF-as-a-Service for a couple of years, and multiple clients use it. We are an MSP, so we provide that solution.
I did not previously use a different solution before Barracuda WAF-as-a-Service.
I have not seen a return on investment with Barracuda WAF-as-a-Service, but I can say it is good.
My experience with pricing, setup cost, and licensing for Barracuda WAF-as-a-Service is that it is good. The pricing is normal, and everything is normal, so it is good.
I do not have anything else to add about how I use Barracuda WAF-as-a-Service or any other interesting scenarios I have seen with my clients. Everything is good regarding the features or how they compare to other solutions. I would say that Barracuda WAF-as-a-Service's accuracy and reliability of output is between 50 and 60 percent. I give this product a rating of 7.