Barracuda Web Application Firewall’s most valuable features are real-time threat detection and automatic security updates.
IT Project Manager at Brilliant telecommunications
Has good technical support services, but the functionality is complicated to understand
Pros and Cons
- "It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment."
- "The platform's pricing needs improvement."
What is most valuable?
What needs improvement?
The platform's pricing needs improvement.
How are customer service and support?
The technical support services are good.
How would you rate customer service and support?
Neutral
Buyer's Guide
Barracuda Web Application Firewall
June 2025

Learn what your peers think about Barracuda Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
855,347 professionals have used our research since 2012.
Which solution did I use previously and why did I switch?
I have used Fortinet before. It has efficient AI capabilities compared to Barracuda.
What was our ROI?
The product has generated around 10% of return on investment.
What's my experience with pricing, setup cost, and licensing?
The product is expensive. It is overpriced.
What other advice do I have?
The product works effectively. However, it is complicated to understand and requires essential knowledge. It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment. We can identify and block malicious URLs. With proper training, it is easy to manage templates and policies for this tool. They provide comprehensive documentation and training courses available for free on their website. It has good features for forensic analysis and reporting. It has a user-friendly interface and seamless integration with SQL.
I rate it a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner

Technical Program Manager, Security - Mergers at a tech vendor with 10,001+ employees
Stable, great visibility, with smooth deployment.
Pros and Cons
- "The most valuable feature is the rule set."
- "I would like to see a native multi-cloud cover."
What is our primary use case?
Our primary use case is for web applications utilizing it primarily for DDoS and cross-site script protection.
How has it helped my organization?
Our organization has improved because it has created a new layer of security analytics. Typically we used to do study code analysis, but then by adding that capability we now have dynamic analysis, which is very difficult to attain unless you have a technology. So now we have not only the visibility on any denial of service attacks, but we also have the ability to defend it.
What is most valuable?
The most valuable feature is the rule set, the ability to specify IP addresses that are excluded. Having the ability therefore to build rules, and exclude specific domains or websites, is very helpful. And when I compare it with some technologies I have used prior to that, which is Signal Science WAF and such. So how the rule set is handled is actually quite nice.
What needs improvement?
I would like to see a native multi-cloud cover. Right now if I have applications that run both on Amazon and Google, I have to have two distinct licenses and two distinct implementations. But we are multi-cloud, so I do not want to have to deploy policies on essentially two apps that are essentially the same policies. I would prefer to have a multi-cloud console, in other words, one set of policies that apply to multiple implementations.
For how long have I used the solution?
I have been working with Barracuda Web Application Firewall for the past two years.
What do I think about the stability of the solution?
There is great stability.
What do I think about the scalability of the solution?
It is pretty scalable. Because it is a cloud feature, the elasticity comes from the elastic cloud capability, If you make the wrong configurations it is not going to work. We can be working with anywhere between one thousand to twenty-five thousand.
What about the implementation team?
The deployment took around three months to deploy and we used a third party.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable.
What other advice do I have?
On a scale of one to ten, I would rate Barracuda Web Application Firewall an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Barracuda Web Application Firewall
June 2025

Learn what your peers think about Barracuda Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
855,347 professionals have used our research since 2012.
Network Security and Infrastructure Engineer at a tech services company with 201-500 employees
Good security for layer seven but repeat issues with appliance failures and system crashes
Pros and Cons
- "The solution ensures layer seven is secure from attacks."
- "There are issues when upgrading firewalls and we experience different issues across customers."
What is our primary use case?
Our company uses the solution to provide customers with a proxy service that secures transcriptions as part of a seven-layer process. We currently provide this service to twenty customers.
What is most valuable?
The solution ensures layer seven is secure from attacks.
The scripting is good.
What needs improvement?
Layer four could be more secure like layer seven to prevent HTTP and HTTPS attacks.
There are issues when upgrading firewalls and we experience different issues across customers. The communication metrics, ports, traffic, source, destination, and service must be enabled to upgrade firmware but there is no documentation or article for opening the communication matrix to upgrade smoothly.
STM crashes are a repeat issue and they wipe out appliances. Each time, we have to open a ticket with support and get Apache to fix the issue. It is unclear why appliances have issues or fail and need to be recovered with Apache.
Firmware upgrades cause automatic configuration changes without providing notifications. Configurations such as ports should not be changed automatically because they negatively affect customers. One customer's configuration issue was within the third layer and took seven days to solve. Support mitigation and work describes policies created automatically after upgrading firewalls but we already created and want to retain our own policies.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the stability of the solution?
The solution is stable but ongoing issues with appliance failures, system crashes, and upgrading firmware affect its smooth operation.
How are customer service and support?
I opened a support ticket for resolving issues when upgrading firewalls. Support could not get to the issue and did not inform me to check traffic on the firewall. It is important to determine what is plugged in when a parameter is trying to communicate outside to download and upgrade firmware to the latest version. The issue was ongoing for three months until I accidently detected it myself.
Tickets are not solved in one day and sometimes I have to close tickets without any solution from support. Only tickets at the second or third escalation level receive support.
How was the initial setup?
The setup is straightforward and installation can be finished in one day.
What about the implementation team?
We implement the solution for customers.
What's my experience with pricing, setup cost, and licensing?
The solution is based on a licensing model and might be $360 for the hybrid version.
Which other solutions did I evaluate?
We have to migrate to another vendor because the solution no longer supports issues with the stack hub.
We are a partner with Barracuda so recommend the application firewall to our customers but we now have thirteen customers who use Azure stack hub and cannot receive support. We communicated this issue with Barracuda's Middle East management and they suggested using a container as a service. We tried this in our lab but had issues with the installation which we finally resolved. We have some concerns about data being exposed because it is in the cloud. Our customers are administrators and will not accept their data being exposed.
We would rather work with Barracuda because we have experience with their application firewalls and that makes it easier to support customers. We will have to go to another vendor and take classes to become experts.
What other advice do I have?
I rate the solution a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cyber Security Consultant at a engineering company with 10,001+ employees
Stable and scalable solution with a straightforward setup, good performance, and fast support response time
Pros and Cons
- "Setup of this solution is straightforward. It's a stable and scalable solution, with good performance and fast technical support."
- "The GUI needs to be improved because it sometimes hangs and needs to be restarted."
What is our primary use case?
This solution is being used as a requirement for architect reference.
What is most valuable?
The Barracuda Web Application Firewall is more than perfect. It's a near-optimal solution. It has good performance.
What needs improvement?
The graphical user interface (GUI) of this solution needs improvement. Sometimes it hangs, so you'll need to restart it.
We have a problem with the license because we are unable to migrate the license from a permanent license to a one-year license, or from a temporary license to a permanent license. This is a critical point because we need support from the Barracuda team for this, all the time. They can't change it successfully from their side.
When you start on the licensing, usually during the deployment, we give the customer a temporary license. You can create this token from the website, then when the customer buys the license, you need to upgrade the current license from a one month license to a permanent license for one year, two years, or three years, depending on the license.
Sometimes, when we are uploading from the old verification, e.g. from the old token to the new token, the VM hangs, and we'll need support from Barracuda's side: from the backend. Their support team does it like this, and helps us from their side.
The firewall is a little bit complicated.
For how long have I used the solution?
We've used this solution since last year.
What do I think about the stability of the solution?
The Barracuda Web Application Firewall is stable.
What do I think about the scalability of the solution?
I find this solution scalable.
How are customer service and support?
Technical support for this solution is acceptable. Sometimes the technical support takes longer because they could have a heavy load, or don't have much time to respond to all of the tickets at once, but that's normal.
How was the initial setup?
The basic setup of this solution is straightforward, and it was nice for us.
What other advice do I have?
We're still using the Barracuda Web Application Firewall, but not as much as we used to. We were using it more last year. Usage of it has been reduced, and I don't know why. It's up to the customer, and not up to me. I cannot select for the customer. I cannot change what the customer desires.
I'm still working with this solution, but not as frequently as I did last year. We had a lot of projects dedicated to the Barracuda Web Application Firewall last year. Now, not all of our customers prefer this product, and I don't know why.
The Barracuda Web Application Firewall works on the VM (virtual machine) on Azure cloud. Usually, when you install this solution, the template will provide you the latest version of the Barracuda Plus. On the Azure cloud, we use the JSON template from GitHub.
I can't explain the use case in detail because I'm working with government entity, so it's classified information.
The Barracuda Firewall is a little bit different, when compared to other firewall related products. These products don't have the same interface, sequence, or process, but the Barracuda Firewall has its own character. I noticed this on the firewall, not the WAF.
The deployment and maintenance of this solution requires more than 10 people.
I'll tell people looking into implementing the Barracuda Web Application Firewall that it's one of the best products in the market, and I totally recommended it. Even their support is able to respond fast to our licensing issues.
I'm rating the Barracuda Web Application Firewall a nine out of ten. No solution can get a ten. This solution deserves between an eight and nine rating. I'm putting it as a nine.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Presales Engineer at SNSIN
Easy to deploy and has very good technical support
Pros and Cons
- "Some of the most valuable features are the ease of deployment, the Barracuda support, the easy-to-use console, and the granularity of the reports."
- "Barracuda Web Application Firewall's load balancing feature could be improved."
What is our primary use case?
Our primary use case of this solution is protection of applications. If you have applications, for instance, in Azure, and you want to protect them, you can use Barracuda Web Application Firewall, and you have any input data available. This is one of the best use cases.
For this solution, we have both cloud-based and VM for Azure.
What is most valuable?
Some of the most valuable features are the ease of deployment, the Barracuda support, the easy-to-use console, and the granularity of the reports.
What needs improvement?
Barracuda Web Application Firewall's load balancing feature could be improved.
For how long have I used the solution?
I have been using Barracuda Web Application Firewall for four years.
What do I think about the scalability of the solution?
In our organization, there are around 1,200 to 1,800 users of this solution.
How are customer service and support?
I would rate Barracuda's technical support a nine and a half out of ten. The technical support is very good.
How was the initial setup?
The installation is straightforward. There are no hidden challenges or anything. Anybody can do it with the installation guide.
One engineer is more than enough to handle maintenance.
What about the implementation team?
We implemented this solution through an in-house team.
What's my experience with pricing, setup cost, and licensing?
They only offer a yearly licensing plan.
Which other solutions did I evaluate?
There are dedicated web application firewalls like Imperva that allow for enterprise level firewall web apps. The main competitors are FortiWeb and Cloudflare.
What other advice do I have?
I rate Barracuda Web Application Firewall an eight out of ten. Everything—support, efficiency, the tax rate—comes into the picture. I would recommend this solution to others who want to start using it.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Network Security and Infrastructure Engineer at a tech services company with 201-500 employees
Easy to restrict applications and utilize many features and ensures that it's not complicated to work with
Pros and Cons
- "Data leak prevention is very important and ensures protection against attacks."
- "I faced an issue when Barracuda decided not to support Azure Stack Hub anymore, which was a significant issue as we had many customers using it on that platform."
What is our primary use case?
I'm using Barracuda as a web application firewall for any application. It is too smart and user-friendly, making it easy to restrict applications and utilize many features.
How has it helped my organization?
It is very easy to restrict applications and utilize many features and ensures that it's not complicated to work with.
What is most valuable?
The most helpful feature is rate limiting, which acts as a security layer against DDoS attacks. Additionally, data leak prevention is very important and ensures protection against attacks.
What needs improvement?
I faced an issue when Barracuda decided not to support Azure Stack Hub anymore, which was a significant issue as we had many customers using it on that platform. Due to this decision, we had to replace Barracuda with another vendor, which was regrettable.
For how long have I used the solution?
I have been working with Barracuda Application Firewall for more than four years.
What do I think about the stability of the solution?
When the SDM crashed, we experienced instability, yet support usually acted quickly and was very helpful, ensuring stability for customers.
What do I think about the scalability of the solution?
Scalability is strong, rated eight to nine. The solution is capable of meeting scalability requirements efficiently.
How are customer service and support?
Technical support may be rated as eight or nine out of ten. The support is very helpful and responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Due to the decision by Barracuda not to support Azure Stack Hub, we replaced Barracuda WAF with another vendor for more than ten customers.
How was the initial setup?
The setup process is too simple.
What's my experience with pricing, setup cost, and licensing?
On a scale, pricing is nine out of ten. It's a reasonable price for this product.
Which other solutions did I evaluate?
There is no comparison, as Barracuda is too smart. Compared to FortiWeb, Barracuda is much better.
What other advice do I have?
I would rate Barracuda Web Application Firewall at nine out of ten overall. I can recommend it to other users. Barracuda is one of the remarkable vendors in web security and is too smart.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Last updated: Nov 26, 2024
Flag as inappropriateNetwork secur eng at Qatar Free Zone
Great technical support, good stability, and offers reasonable pricing
Pros and Cons
- "Even when we were upgrading to a new OS, we didn't have any difficulties with the product. The stability is good."
- "While the UI is good, it can get a little bit complicated."
What is our primary use case?
We primarily use this solution for security purposes. We use it as a firewall.
What is most valuable?
The interface is great. It's one of the most valuable aspects of the solution.
The visibility we are able to achieve is quite good.
The traffic monitoring is very helpful and the URL filtering has been excellent.
Even when we were upgrading to a new OS, we didn't have any difficulties with the product. The stability is good.
We have found that the technical support is very good.
The pricing of the product isn't overly expensive.
What needs improvement?
While the UI is good, it can get a little bit complicated. It's not like Next-Gen Firewalls. I need to remember all of the tabs. The sub-tabs should be at the right as they are in the Next-Gen. Mostly, Next-Gen firewalls have everything on the left panel and it will reappear. It would be nice if there was a little more consistency.
I only really have one year of experience with the solution. Therefore, it's hard to discuss missing features. I need more time to explore the product first.
For how long have I used the solution?
I have been using the solution for one year.
What do I think about the stability of the solution?
We haven't had any issues with the stability or the performance, even when switching to a new OS. It's reliable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
While the solution may be scalable, I don't have enough background to really comment. I haven't been involved in scaling.
How are customer service and technical support?
Technical support is quite good. That's the main reason everyone is shifting to Barracuda.
It's from India. I'm in the Middle East. Even though the product is from the UAE, the Middle East, the support is from India. They have good engineers that are well-trained. That said, if you need an L3 issue resolved, those engineers are from other regions. Typically an Indian tech will communicate with the other region directly. The support in the case of L3s likely comes from Europe. In any case, everyone is very helpful and responsive, and we are satisfied with the level of support.
How was the initial setup?
The initial setup is not overly complex or difficult. It's easy enough to execute. That said, the burden has to be getting a bit of the knowledge in regards to routing. That's a tricky area. However, it's pretty much the same as a Next-Gen Firewall configuration.
What's my experience with pricing, setup cost, and licensing?
The pricing is okay, however, there are a few other competitors that are a little bit lower. It's still reasonable.
What other advice do I have?
I'm an end-user and a customer.
I would rate the solution at an eight out of ten. Sometimes the solution can be tricky around filtering, which is why I don't give it perfect marks.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr IT Manager at a financial services firm with 11-50 employees
Stable product with a simple setup process
Pros and Cons
- "The product has fantastic support services."
- "We encountered a few glitches while implementing API security features into the product."
What is most valuable?
The product has fantastic support services. It provides complex solutions, including block mode and other default protection features.
What needs improvement?
We encountered a few glitches while implementing API security features into the product. Secondly, they could provide transparency for different types of protection parameters available. It will be beneficial if there is some visibility for the same. We faced some downtime issues the last two times due to Barracuda infrastructure. Thus, we are searching for alternate WAF solutions.
For how long have I used the solution?
We have been using Barracuda Web Application Firewall for two years.
What do I think about the stability of the solution?
I rate the platform's stability a ten out of ten.
What do I think about the scalability of the solution?
I rate the product's scalability nine out of ten. It is suitable for enterprise businesses.
How are customer service and support?
The technical support services are fantastic. They share the knowledge transparently. This feature is more exceptional than that of other vendors.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup process is simple. We have deployed the product on the cloud.
What other advice do I have?
I rate Barracuda Web Application Firewall a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Barracuda Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Imperva Web Application Firewall
Radware Alteon
The Fastly Next-Gen WAF (powered by Signal Sciences)
Buyer's Guide
Download our free Barracuda Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Imperva WAF vs. Barracuda: Which One is Better?
- Which is better, Barracuda Web Application Firewall or F5 Advanced WAF?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy