No more typing reviews! Try our Samantha, our new voice AI agent.

Share your experience using The Fastly Next-Gen WAF (powered by Signal Sciences)

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 114,000+ reviews on PeerSpot:

reviewer2857998 - PeerSpot reviewer
Systems & Cloud Architect at a computer software company with 11-50 employees
Real User
Top 5Leaderboard
Jun 16, 2026
Improved web security has protected public apps from DDoS while support and cloud availability need work
Pros and Cons
  • "Barracuda WAF-as-a-Service has never failed us so far; it is good, and we have not seen any clients complaining that it is not doing its job, failing, freezing, or hanging."
  • "I think Barracuda WAF-as-a-Service can still do better on the DLP side."

What is our primary use case?

Our main use case for Barracuda WAF-as-a-Service with clients is to secure their environments, especially for DDoS attacks and security vulnerabilities that we have found. We implement those solutions, and for smaller clients, we also suggest they adopt Barracuda WAF-as-a-Service. It is cheaper compared to other products in the market, but at the same time, it provides sufficient capabilities so clients can get started.

A recent situation where I recommended Barracuda WAF-as-a-Service to a client involved a security breach because their firewall was a different model from a different vendor and was not able to handle the breach or address the security concerns. We then recommended they adopt Barracuda WAF-as-a-Service. After implementing that solution, we resolved many attacks. Attacks continued to occur, but this time Barracuda WAF-as-a-Service was able to stop them, scan them, and prevent DDoS and DLP attacks. It was a good addition to that environment.

What is most valuable?

The best features Barracuda WAF-as-a-Service offers, in my experience, include bot protection, DDoS, and DLP. DDoS and bot API features are good. DLP does the job, but I would say it is not very good, though it will do the job for you.

When I mention DDoS protection and DLP, I can tell you that these features protect our clients from active DDoS attacks because most of our clients are public companies and well-known companies. Regardless of what kind of firewall or solution is implemented, people keep trying to break in. We see active, almost constant bot and DDoS attacks happening on those environments. Barracuda WAF-as-a-Service has never failed us so far. It is good, and we have not seen any clients complaining that it is not doing its job, failing, freezing, or hanging. It is doing its job.

Barracuda WAF-as-a-Service has significantly improved security in our organization and for our clients because without it, it was always a challenge to see what is happening in the environment, protect against bot attacks, protect against DDoS and DLP attacks, and ensure web protection. After adding this solution, there was a significant improvement in security for that environment.

What needs improvement?

I think Barracuda WAF-as-a-Service can still do better on the DLP side. The DLP side is a little weak, and their SaaS-based model which they provide in Azure and AWS is not very good. If you compare the high availability and fault tolerance of these with other products, I think those other products have advantages. If Barracuda WAF-as-a-Service can improve on availability, especially in public cloud infrastructures, that would be beneficial.

They also need to improve their support. Their support team is not very technical and helpful, and they need to ensure they provide the right person for the right support, especially when a ticket is open. Technically, when someone opens a ticket, they have already completed basic troubleshooting. Barracuda WAF-as-a-Service needs to hire more skilled engineers.

For how long have I used the solution?

I have been using Barracuda WAF-as-a-Service for a couple of years, and multiple clients use it. We are an MSP, so we provide that solution.

Which solution did I use previously and why did I switch?

I did not previously use a different solution before Barracuda WAF-as-a-Service.

What was our ROI?

I have not seen a return on investment with Barracuda WAF-as-a-Service, but I can say it is good.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Barracuda WAF-as-a-Service is that it is good. The pricing is normal, and everything is normal, so it is good.

What other advice do I have?

I do not have anything else to add about how I use Barracuda WAF-as-a-Service or any other interesting scenarios I have seen with my clients. Everything is good regarding the features or how they compare to other solutions. I would say that Barracuda WAF-as-a-Service's accuracy and reliability of output is between 50 and 60 percent. I give this product a rating of 7.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Jun 16, 2026
Flag as inappropriate
Sr. VP of Creative & Development at a non-tech company with 51-200 employees
Real User
Top 5
Dec 26, 2025
AI-driven threat detection has reduced incidents and saved team hours weekly
Pros and Cons
  • "Check Point CloudGuard WAF has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning."
  • "Check Point CloudGuard WAF's support is only available in English."

What is our primary use case?

Check Point CloudGuard WAF's main use case is protecting web application APIs from external threats. It helps us block common attacks like SQL injections, cross-site scripting, and bot traffic, while also ensuring compliance with the security standards.

One unique aspect of our use case for Check Point CloudGuard WAF is how we leverage it to protect customer APIs that are critical to our business. Because we develop and host several in-house applications, we needed a solution that could adapt quickly to new endpoints and traffic patterns. Check Point CloudGuard WAF has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning.

What is most valuable?

The best features Check Point CloudGuard WAF offers include AI-driven threat prevention, protection against OWASP Top 10, and zero-day attacks.

The zero-day attack protection in Check Point CloudGuard WAF has been very effective for us. Instead of waiting for signature updates or manual rule changes, the system uses AI to detect abnormal patterns and block suspicious traffic automatically.

Check Point CloudGuard WAF has positively impacted our organization by strengthening application security while reducing the workload in our team. The AI-driven protection against zero-day attacks and OWASP Top 10 vulnerabilities means threats are blocked automatically before patches are applied. This noticeably reduced the number of incidents we needed to investigate, freeing up time for more strategic projects.

Check Point CloudGuard WAF's ability to preemptively block zero-day attacks is one of its strongest advantages. Instead of relying on traditional signature updates, it uses AI and contextual analysis to spot abnormal traffic patterns and block them before they can exploit vulnerabilities. For example, during the Log4Shell disclosure, Check Point CloudGuard WAF was already blocking the suspicious payloads without us needing to manually adjust rules.

The breach reduction feature of Check Point CloudGuard WAF is one of the most impactful aspects of the solution. It proactively blocks suspicious traffic before it can exploit vulnerabilities, which has noticeably reduced the risk of breach in our environment.

What needs improvement?

Check Point CloudGuard WAF's support is only available in English. I gave Check Point CloudGuard WAF a rating of 9 out of 10 because the language limitation of support keeps it from being a perfect score, as I prefer support in different languages.

For how long have I used the solution?

I have been using Check Point CloudGuard WAF for around six years.

What do I think about the stability of the solution?

Check Point CloudGuard WAF is very stable.

What do I think about the scalability of the solution?

Check Point CloudGuard WAF's scalability is very good, and I have no issues with this.

How are customer service and support?

Check Point CloudGuard WAF's customer support is very great and very fast.

I would give Check Point CloudGuard WAF a rating of 10 for customer support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Azure WAF, but I decided to switch to Check Point CloudGuard WAF.

How was the initial setup?

The first deployment of Check Point CloudGuard WAF was initially difficult because the documentation is not intuitive, but it is no longer an issue.

What about the implementation team?

I do not utilize Check Point CloudGuard WAF alongside any other Check Point products. I prefer to use a centralized WAF or specialist WAF to assess the efficiency improvements provided by Check Point CloudGuard WAF compared to traditional WAFs.

What was our ROI?

I have saved a significant amount of time and resources since implementing Check Point CloudGuard WAF. Before, our teams often spent several hours manually tuning rules and chasing false positives. The detection has now cut the workload by more than half, freeing up three or four hours less per week.

Check Point CloudGuard WAF has reduced our total cost of ownership by approximately 10%. I consider the time saved as a return on investment since using Check Point CloudGuard WAF.

What's my experience with pricing, setup cost, and licensing?

The pricing, setup cost, and licensing for Check Point CloudGuard WAF are excellent, and I have no concerns with them.

Which other solutions did I evaluate?

I did not evaluate other options before choosing Check Point CloudGuard WAF.

What other advice do I have?

Check Point CloudGuard WAF is an excellent security tool, and my advice to others looking into using it is that it is complete and modern. Check Point CloudGuard WAF is an excellent solution for web applications, and you should consider it for future deployments. I would rate this product 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Dec 26, 2025
Flag as inappropriate