No more typing reviews! Try our Samantha, our new voice AI agent.

Barracuda Application Protection vs Wallarm NG WAF comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Barracuda Application Prote...
Ranking in API Security
10th
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Wallarm NG WAF
Ranking in API Security
14th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
5
Ranking in other categories
Web Application Firewall (WAF) (39th)
 

Mindshare comparison

As of May 2026, in the API Security category, the mindshare of Barracuda Application Protection is 2.1%, up from 0.0% compared to the previous year. The mindshare of Wallarm NG WAF is 3.9%, up from 3.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
API Security Mindshare Distribution
ProductMindshare (%)
Barracuda Application Protection2.1%
Wallarm NG WAF3.9%
Other94.0%
API Security
 

Featured Reviews

Salbu Kumar - PeerSpot reviewer
Manager at Cyvogenix
Application protection has strengthened web security and reduces manual effort for critical services
One area where Barracuda Application Protection could be improved is reporting customization. The dashboards are useful, but more flexible executive-level and technical reporting options would help different teams. Another area is policy tuning for complex applications. While the platform is strong overall, some advanced environments need extra fine-tuning to reduce false positives or adapt custom rules. Deeper integrations with third-party CM and DevSecOps workflows would streamline operations further. Overall, it is a solid platform, but more customization and smoother advanced tuning would make it even better. A simpler onboarding experience for new administrators would be beneficial. The platform has many strong features, but teams without deep WAF experience may need time to become fully comfortable with advanced settings. More AI-driven recommendations for rule tuning, anomaly prioritization, and false positive reduction would help smaller teams operate more efficiently. Another area is pricing flexibility for growing organizations or mid-sized businesses. Overall, the product is strong, but easier management and smarter automation would make it even more attractive.
it_user796242 - PeerSpot reviewer
Information Security Engineer at a tech vendor with 51-200 employees
Helps us to monitor attacks to our sites and prevents a lot of them
Set up Wallarm as a reverse proxy. Do not replace your web server. Use Wallarm first in monitoring mode, then learn from Wallarm which type of request is false positive and which type of request is not. This process takes a couple of weeks for very highly-loaded web applications (few millions of unique visitors in one month). Then you can turn Wallarm into blocking mode and everything will be fine. Do not forget to build a monitoring system, the wave, and API for it. Before we started using Wallarm, I already knew Ivan (CEO) and Stepan (COO) from a couple of years before. Ivan had his own security company and Stepan was working on a Russian security magazine called Xakep. They told us that they wanted to create a new WAF and already had a working version of it. They asked me to test it. We did tests, and it was really good. After few month after testing, we signed an agreement. Our choice was made not because we knew these guys for a long time, but because the product was really cool and we were glad to start using it as one of the first on the market!

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Barracuda Application Protection has positively impacted my organization as it is used for multiple clients, and I am also backing up the Exchange servers, which frequently experience attacks in customer environments, allowing for quick restoration, even from yesterday or the day before yesterday."
"Barracuda Application Protection's best features are protecting APIs and defending against zero-day vulnerabilities."
"Barracuda Application Protection has been a solid and dependable solution for protecting public-facing applications."
"Barracuda Application Protection had a positive impact mainly in terms of improved visibility and better handling of automated attack traffic."
"Barracuda Application Protection has significantly improved security posture, reducing the attack surface using WAF plus API protection, automating threats with machine learning-based bot protections, providing zero-trust access to applications, and helping detect and mitigate threats in real-time, resulting in a 50 to 60% reduction in security incidents after deployment."
"Within the first six to seven months of deployment, I saw a 60% reduction in security incidents, incidents affecting the web application which directly translated into fewer service interruptions and less time spent on incident response."
"Within the first six months of deployment, we have seen a 60% reduction in security incidents affecting the web application, which directly translated into fewer service interruptions and less time spent on incident response."
"Barracuda Application Protection has positively impacted my organization by managing traffic well, enhancing access security, operational efficiency, and user experience, leading to customer satisfaction."
"They are the only solution that fits our success criteria and business objectives: WAF must have a low (<5%) false negative rate and be ready to protect from all well-known web attacks."
"With active threat detection, we are no longer over-swamped with tons of useless events."
"Perimeter control and active vulnerability scanner are the most valuable features."
"The most powerful feature is the ability to first learn what type of query to make to your web application when it is attacked and what type of query creates a false positive to your app."
"Vulnerability scanner and WAF are valuable features."
"Helps us to monitor situation in regards to attacks to our sites and prevents a lot of them."
 

Cons

"I do not have much to say about the improvement, but a more innovative solution for sniffing more on the network would be great, and having the advanced ability to close off ports when they could be getting tested from hackers for intrusion would be helpful."
"Additionally, I can say that deeper API security features such as automation, API discovery, scheme validations, and improved protections for modern environments are needed."
"My only concerns are that it is not very user-friendly and the response time is slow."
"The interface of Barracuda Application Protection is generally intuitive but can become complex for advanced configurations."
"One area where Barracuda Application Protection can improve is in policy tuning and ease of configuration, especially for complex application and API-heavy environments."
"Barracuda Application Protection could be improved with a more user-friendly interface to enable all types of people to be able to use it, especially the less technical users."
"Improving the operating system structure, firmware, and overall performance would enhance loading times for devices."
"Another area is pricing flexibility for growing organizations or mid-sized businesses."
"Technical support is 6 or 7 out of 10. Sometimes we have had trouble with communication and understanding."
"The biggest problem for us was the stability and speed using the first version of Wallarm."
"The biggest problem for us was the stability and speed using the first version of Wallarm. Now, it is fine."
"There were several stability issues during the first pilot."
"Wallarm uses a learning mechanism to detect attacks and to avoid false positives. If Wallarm blocks some illegitimate request, then you can go to the management console and mark this request as false positive, but sometimes this does not work properly."
"It needs more customization in PDF reports."
 

Pricing and Cost Advice

Information not available
"​Pricing must be cheaper than the competition and the licensing must be good.​"
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
894,738 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
20%
Financial Services Firm
20%
Transportation Company
20%
Construction Company
6%
Financial Services Firm
18%
Government
12%
Manufacturing Company
10%
Insurance Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise2
Large Enterprise25
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Barracuda Application Protection?
My experience with pricing, setup cost, and licensing is that I feel it is a bit costlier, but the features that it provides are good. However, I am not the one making decisions on costing and limi...
What needs improvement with Barracuda Application Protection?
I believe Barracuda Application Protection could be significantly improved with better usability and integration with other tools. Barracuda Application Protection's WAF serves as a primary defense...
What is your primary use case for Barracuda Application Protection?
My main use case for Barracuda Application Protection encompasses most of their capabilities. I have used it for APIs, protecting applications, and securing applications for these types of instances.
Ask a question
Earn 20 points
 

Also Known As

No data available
Wallarm NG-WAF
 

Overview

 

Sample Customers

Information Not Available
Panasonic. Miro. Rappi. Wargaming. Gannett. Omio. Acronis. Workforce Software. Tipalti. SEMRush.
Find out what your peers are saying about Barracuda Application Protection vs. Wallarm NG WAF and other solutions. Updated: April 2026.
894,738 professionals have used our research since 2012.