Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (13th)
Barracuda Web Application F...
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
44
Ranking in other categories
Web Application Firewall (WAF) (17th)
Fortinet FortiWeb
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
96
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Carlos Alam Hernandez Baruch - PeerSpot reviewer
Fast and secure deployments simplify operations for government and fintech clients
It is a fast and secure DNS. It is very easy to deploy, and my customers are happy with this tool. Additionally, the CDN performance in Mexico is excellent, providing fast service and tools. It offers reliability during high-traffic periods, ensuring no impact on the environment. It helps my clients avoid using on-premise boxes, simplifying operations as they only use the prices on Cloudflare.
Anne-Aimee Wollerich - PeerSpot reviewer
Managing bot traffic effectively enhances usability for non-technical users
Barracuda Web Application Firewall ( /products/barracuda-web-application-firewall-reviews ) lacks some of the more specified and structured features offered by solutions like Tenable. Although Tenable is more expensive and less easily deployable, its features are more deepened and chiseled, particularly for IT personnel. For example, Tenable provides more comprehensive dark web scanning capabilities, which Barracuda could improve upon.
OcheEluma - PeerSpot reviewer
Enhanced security with comprehensive traffic inspection and some downtime automation needs
One area that needs improvement is the handling of SaaS downtime. When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well. Although measures like built-in redundancy and manual switching between data centers exist, there is room for improvement in making these transitions automatic without impacting the customer. Automating the migration without manual intervention would significantly enhance user experience during downtime. Additionally, being able to read non-flagged traffic for operational purposes could also be an area to improve.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"The solution provides good load balancing and protection against DDoS attacks."
"The solution is very good at mitigating threats."
"Centralized, full-featured DNS."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"Easier http to https redirect using page rules"
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"It is stable and the performance is good."
"The most valuable feature of this solution is the simplicity of configuration."
"What I like most about Barracuda Web Application Firewall is its availability. I also like that it's an easy-to-use solution."
"The solution is user-friendly and easy to set up."
"You don't need help from Barracuda to help with the deployment. The deployment is easy."
"We run it with no downtime, because it has good support."
"The most valuable features of Barracuda Web Application Firewall include advanced bot protection, DDoS protection, and addressing the top ten vulnerabilities."
"The product has fantastic support services."
"This product is very user-friendly."
"The anti-defacement feature is very useful because it looks for web changes over time to protect pages."
"It allows specific IP whitelisting or even regional whitelisting, ensuring only whitelisted traffic from certain geographical regions can access the environment."
"We were able to protect our web servers from outside attacks."
"The most valuable feature is that this product represents a whole solution, including a WAF, and even anti-defacements."
"The initial setup is pretty straightforward."
"We can block access using the IP address so no one can connect to our web server or website using the real IP."
"The solution is stable."
 

Cons

"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"Cloudflare could be improved by introducing a mid-tier pricing option."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"Latencies are always a problem."
"The tool needs to improve caching of servers. The product needs to include PFX certificate as well."
"The solution could be more user-friendly."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"There are some vulnerabilities that are reported across the tools offered by Barracuda for some devices, which need to be taken care of from an improvement perspective."
"Sometimes when we put it in action, we have some blogs that appear as false positives. I think that it's improving. Barracuda should minimize false positives."
"As a service, Barracuda needs to host in Saudi Arabia, as they currently don't have this functionality."
"There's potential for improvement in the platform's CMS integration."
"There are issues when upgrading firewalls and we experience different issues across customers."
"We get false positives about phishing emails."
"It would be better if their updates would be released annually."
"The solution could use more reports."
"The dashboards are not that configurable. Application-specific dashboards can be improved. If we have 50 applications, there should be something to see what's happening with these 50 applications. There could be a graph or a consolidated alert page where all alerts are inbuilt. They have other products that I can use, but this feature should be built into FortiWeb."
"The dashboard evaluating the performance of each application connected to the web app's firewall is quite helpful, but the tool is only available in application performance management. So I think if Fortinet could better integrate that particular feature, it would add a lot of value to the product."
"FortiWeb does not exist in a cloud-based form. Its only available for deployment as a virtual appliance on AWS and Azure IaaS platforms. Because of the trend to WAF environments, it would be good to have it as a SaaS. Also, FortiWeb would be more competitive if it combined WAF and DDoS protection."
"The F5 solution has more features than Fortinet FortiWeb, such as multiple load balancing."
"We use Kubernetes, so I would like to have a plugin to configure FortiWeb Cloud automatically using Kubernetes Ingress. That would reduce the complexity of setting up an Ingress object in Kubernetes. Some competing solutions help you configure Ingress and Kubernetes automatically."
"The initial setup depends on familiarity with the product. It's manageable with the right expertise."
"F5 and some other firewalls are easier to customize. FortiWeb could be more flexible and customizable. The documentation could also be improved because many of the advanced features aren't fully documented."
"I see no room for improvement at the moment."
 

Pricing and Cost Advice

"The product's pricing is minimal compared to other products."
"The tool is a premium product, so it is very expensive."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"That is one of the great features. I was able to access the majority of the features and services for free."
"A free version of the solution is available."
"The price is reasonable."
"There are no additional costs beyond the standard licensing fees."
"The product pricing was competitive for the value it offers regarding security features."
"The price of the solution is a little expensive. There is a license for this solution and it can be purchased every one, two, or five years."
"The Barracuda Web Application Firewall is quite expensive."
"Barracuda costs us $8,000 per year. Barracuda costs $20,000 for a full subscription, when you try to protect multi-site infrastructure, in different geographical zones and for different data centers. If you have only one site, Barracuda will be cheaper."
"For small companies, the price is very expensive because the WAF is an enterprise-level application, not intended for smaller businesses. In my opinion, the price is right for enterprise-level use."
"Cost is a bit on the higher side. Big companies can afford it."
"Our licensing fees are paid annually and the cost is between €600 and €800 (approximately $665.00 to $885.00 USD)."
"The price is reasonable, more so than other products."
"There's only one payment for the duration of the license. On a scale from one to five, I would rate pricing at four. I have not encountered any additional costs on my projects involving Fortinet FortiWeb."
"​The pricing is reasonable."
"​It really pays off to buy licences for multiple years​."
"Its subscription prices are cheaper, and it is not very expensive. From a price perspective, Fortinet is a very well-known security vendor. Subscriptions are very simple. They have a couple of licenses on an appliance, and that's it. The cost is not that big. One license is 40K, which they give with all the products. Another one includes the subscriptions for threat prevention, IPS, sandboxing, etc, which is more than enough."
"It is not a cheap product. It is not like a Linux or a Genex that you can deploy. It is a hardware appliance, and it is built for a specific reason and reliability. It is an enterprise-class solution. You wouldn't find an SMB investing in something like this."
"Cheaper than others."
"All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500."
"The solution is a bit expensive when compared to other products."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
863,901 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Comms Service Provider
11%
Financial Services Firm
10%
Manufacturing Company
7%
Computer Software Company
18%
Financial Services Firm
8%
Educational Organization
7%
Manufacturing Company
6%
Computer Software Company
13%
Financial Services Firm
11%
Government
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs...
What is your primary use case for Barracuda Web Application Firewall?
Our primary use case was to track the traffic on websites or webshops to identify potential malicious actors, such as...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
The pricing for Barracuda is quite high compared to other OEMs. Each transaction requires my purchase team to negotia...
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing for Fortinet FortiWeb varies with different models having different prices. It depends on the requirement...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in Fortinet FortiWeb. The team was only from FortiGate itself. They are making new firm...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Barracuda Web Application Firewall vs. Fortinet FortiWeb and other solutions. Updated: July 2025.
863,901 professionals have used our research since 2012.