No more typing reviews! Try our Samantha, our new voice AI agent.

Barracuda Web Application Firewall vs Fortinet FortiWeb vs Imperva Application Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.6
Cloudflare WAF offers quick ROI, crucial protection for e-commerce, saves bandwidth, and balances cost with valuable free features.
Sentiment score
6.7
Barracuda Web Application Firewall ensures cost-effective security, delivering 10% ROI and crucial protection during challenging times like the COVID pandemic.
Sentiment score
6.5
Fortinet FortiWeb offers cost-effective security, reducing expenses by up to 80%, enhancing reliability, and mitigating cyber threats.
Sentiment score
6.1
Imperva Application Security Platform provides high ROI through cost savings, enhanced security, and compliance benefits, especially in critical sectors.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
Owner at Hga consulting
My development team is working on the latest language tools or applications, so until then, this web application firewall is essential in my network to protect my existing online assets or software.
Director Information Technology at College of Physicians & Surgeons Pakistan
We have seen a return on investment as the manual work for monitoring attacks and generating reports is reduced significantly, saving money.
Senior Security Systems Engineer at a tech services company with 11-50 employees
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
Head of Sales Services Department at a comms service provider with 51-200 employees
I was able to save over seven million dollars last year as return on investment in the company.
Senior Cybersecurity Consultant at Cyberoutcome Limited
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time.
Presales Engineer at a tech services company with 11-50 employees
 

Customer Service

Sentiment score
6.3
Cloudflare WAF support is mixed; responsive for some, but Indian customers face call availability and administrative issues.
Sentiment score
6.6
Barracuda Web Application Firewall support is effective but varies by location, technician expertise, and response times.
Sentiment score
6.6
Fortinet FortiWeb's support is responsive and competent, though users note room for improvement in expertise and response times.
Sentiment score
6.9
Users appreciate Imperva's technical support for expertise but suggest improvements in customer service response times for better experience.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
Owner at Hga consulting
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
IT Manager at Amla Commerce
I would rate customer support a solid ten, as they are consistently on top of every issue, addressing them without delays and providing excellent support twenty-four hours a day, seven days a week.
Senior Security Systems Engineer at a tech services company with 11-50 employees
The customer service and support from Barracuda have been excellent.
Technical Lead at cmsit services
The customer service and support are exceptional, and I would give them a ten out of ten.
Cyber Security Consultant at Axle iT
Their support is truly exceptional when I compare it with similar large-sized companies.
Global Channel Alliances Lead at a tech vendor with 10,001+ employees
The expertise of engineers varies across different time zones, affecting the effectiveness of the support provided, especially during our daytime.
Chief Technology Officer at Future Point Technologies
The back-end development team is available, and if any issue arises, they will help us immediately by providing solutions when contacted.
Technical Support Engineer at Intimesolutions
I would rate the technical support of Imperva DDoS as ten.
Head of Sales Services Department at a comms service provider with 51-200 employees
They need to work faster on the response time because of issues of urgent replies.
Senior Cybersecurity Consultant at Cyberoutcome Limited
Responsive support addressing urgent needs.
Cybersecurity Consultant at Accenture Singapore Services Pte Ltd
 

Scalability Issues

Sentiment score
7.7
Cloudflare Web Application Firewall offers impressive scalability and automated management, but additional features may incur costs for smaller organizations.
Sentiment score
6.6
Barracuda Web Application Firewall is scalable, with easy upgrades, though physical appliance limitations and configuration issues exist.
Sentiment score
7.1
Fortinet FortiWeb is scalable but limited in hardware upgrades; virtual machines offer more adaptability for various needs.
Sentiment score
7.5
Imperva Application Security Platform offers highly rated scalability, with easier cloud deployment and minor regional challenges noted by users.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
IT Manager at Amla Commerce
The VMSS feature allows for easy upgrades or scaling of virtual editions.
Senior Security Systems Engineer at a tech services company with 11-50 employees
I believe Barracuda Web Application Firewall is quite scalable, and I would rate it as an eight.
Cyber Security Consultant at Axle iT
You can add additional boxes that combine together to achieve a bigger throughput for investigation and research.
Security Team Lead at a outsourcing company with 1,001-5,000 employees
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
Head of Sales Services Department at a comms service provider with 51-200 employees
I have not even needed support after deployment, since it has remained stable.
CTO at Malam Engineering PLC
It is easy to always scale to add more users.
Senior Cybersecurity Consultant at Cyberoutcome Limited
 

Stability Issues

Sentiment score
8.2
Cloudflare Web Application Firewall is praised for stability, high performance, effective protection, daily use, and minimal downtime.
Sentiment score
7.9
Barracuda Web Application Firewall is highly stable and reliable, with occasional performance issues and minor GUI crashes reported.
Sentiment score
7.9
Fortinet FortiWeb is generally reliable, with minimal stability issues, although some users face occasional configuration or version challenges.
Sentiment score
7.9
Imperva Application Security Platform is highly stable and reliable, receiving frequent top ratings despite minor issues.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
IT Manager at Amla Commerce
These result in clients complaining about blocked transactions on a daily basis.
Technical Lead at cmsit services
Barracuda Web Application Firewall is stable in my experience.
Senior Security Systems Engineer at a tech services company with 11-50 employees
We have not faced any significant issues during deployments.
Chief Technology Officer at Future Point Technologies
It is also a stable product without much glitch or downtime.
Senior Presales Consultant at Techlab security
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
CTO at Malam Engineering PLC
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Room For Improvement

Cloudflare WAF needs feature enhancements, better usability, improved support, advanced DDoS protection, and solutions for latency and alerts.
Barracuda Web Application Firewall needs improvements in log storage, interface, API security, scalability, pricing, support, and documentation.
Fortinet FortiWeb needs improvements in upgrades, support, threat intelligence, user interface, cloud integration, reporting, stability, and load balancing.
Imperva needs to enhance failover, SIEM integration, GUI, analytics accuracy, real-time visibility, and pricing for better user experience.
The product can improve by having more multitenancy capability, which is currently not available.
Network Architect at a computer software company with 11-50 employees
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
Owner at Hga consulting
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
CTO at PlayNirvana
Reducing false positives must be a priority.
Director Information Technology at College of Physicians & Surgeons Pakistan
The issues with false positives affect client transactions, leading to complaints about blocked transactions.
Technical Lead at cmsit services
Tenable provides more comprehensive dark web scanning capabilities, which Barracuda could improve upon.
Cyber Security Consultant at Axle iT
If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful.
Technical Support Engineer at Intimesolutions
Fine-tuning is a room for improvement in Fortinet FortiWeb.
Joint Director at PAA
After the customer submits a specific question and requests troubleshooting help from Fortinet support, it takes at least three to five days to provide a proper answer.
Security Team Lead at a outsourcing company with 1,001-5,000 employees
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
CTO at Malam Engineering PLC
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Head of Sales Services Department at a comms service provider with 51-200 employees
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
Senior Presales Consultant at Techlab security
 

Setup Cost

Cloudflare Web Application Firewall offers affordable, flexible pricing with no upfront costs, noted for competitiveness and included support services.
Barracuda Web Application Firewall offers competitive pricing with negotiable terms, despite being costly for some European users.
Fortinet FortiWeb provides flexible pricing and licensing, appealing to enterprises for cost-effectiveness despite some users noting variable costs.
Impera's pricing varies widely; high costs are offset by advanced features, but complex licensing may limit website protection.
I requested a quote from Barracuda's UK team, which was half the price I was quoted in Pakistan.
Director Information Technology at College of Physicians & Surgeons Pakistan
The pricing for Barracuda is quite high compared to other OEMs.
Technical Lead at cmsit services
They are competitive when compared to other vendors including F5 and Imperva, who tend to have higher prices.
Senior Security Systems Engineer at a tech services company with 11-50 employees
For VM machines, the price increases based on CPU configurations of 2, 4, or 8 CPUs.
Presales Engineer at SAUDI PARAMOUNT COMPUTER SYSTEMS
Most security products charge less at the time of purchase because of competition, but when we go to renewals, the prices become very high.
Joint Director at PAA
Fortinet FortiWeb is cost-effective compared to solutions like F5.
Chief Technology Officer at Future Point Technologies
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
Head of Sales Services Department at a comms service provider with 51-200 employees
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor.
Senior Cybersecurity Consultant at Cyberoutcome Limited
The pricing is not transparent to me; it's what the vendors give, or whatever the channel partner offers that you can negotiate on.
Head of Tech at CRC Credit Bureau Limited
 

Valuable Features

Cloudflare Web Application Firewall provides comprehensive security features, easy setup, scalability, and competitive pricing with praised performance and stability.
Barracuda Web Application Firewall enhances security and efficiency with features like bot management, real-time threat detection, and DDoS protection.
Fortinet FortiWeb provides advanced security features and seamless integration, offering cost-effective, robust protection and easy deployment for enterprises.
Imperva's platform offers robust DDoS protection, threat intelligence, and seamless cloud integration, enhancing security and performance with user-friendly management.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
Network Architect at a computer software company with 11-50 employees
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
IT Manager at Amla Commerce
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
Owner at Hga consulting
The most valuable features of Barracuda Web Application Firewall include advanced bot protection, DDoS protection, and addressing the top ten vulnerabilities.
Technical Lead at cmsit services
This process protects against attacks including SQL injection or cross-site scripting, where Barracuda Web Application Firewall will block any request that matches attack signatures.
Senior Security Systems Engineer at a tech services company with 11-50 employees
The most valuable feature of Barracuda Web Application Firewall is managing bot traffic.
Cyber Security Consultant at Axle iT
Fortinet FortiWeb has positively impacted my organization because most of our servers and applications are secure from hackers and other security threats.
Joint Director at PAA
Fortinet's pricing is way more competitive than Cisco or Palo Alto.
Global Channel Alliances Lead at a tech vendor with 10,001+ employees
The machine learning-based threat detection is significant, as it uses a learning method that eases the configuration burden, making it very useful.
Chief Technology Officer at Future Point Technologies
The API security feature is particularly valuable because most attackers do not try to come in from where it is expected.
Senior Cybersecurity Consultant at Cyberoutcome Limited
If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address.
SOC Analyst L1 at CMS-IT-SERVICES-PVT-LTD
It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva.
IT Security Analyst & Engineer (Project, Remote) Australia-Europe at a manufacturing company with 10,001+ employees
 

Mindshare comparison

As of April 2026, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 4.7%, down from 7.2% compared to the previous year. The mindshare of Barracuda Web Application Firewall is 1.9%, up from 1.9% compared to the previous year. The mindshare of Fortinet FortiWeb is 6.5%, down from 8.3% compared to the previous year. The mindshare of Imperva Application Security Platform is 7.6%, up from 7.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
Fortinet FortiWeb6.5%
Imperva Application Security Platform7.6%
Cloudflare Web Application Firewall4.7%
Barracuda Web Application Firewall1.9%
Other79.3%
Web Application Firewall (WAF)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Shahzad Abid - PeerSpot reviewer
Director Information Technology at College of Physicians & Surgeons Pakistan
Has protected our legacy applications effectively but has required constant manual filtering due to false positives
I assess the effectiveness of the machine learning-driven threat detection in Barracuda Web Application Firewall as sometimes behaving abnormally, often showing me false positive attacks, so I have to fix these attacks from time to time. From a stability point of view, I would definitely rate Barracuda Web Application Firewall a seven out of ten. There is definitely some room for improvement; nothing is perfect in the world. I am not satisfied with the technical support from Barracuda. I am somewhat disappointed with the technical support that I have received so far. Whenever I generate a ticket for my problem, it goes to the Indian support team, and they all the time start with the most junior team member, consuming all my precious time. At the end, I have to close that ticket without any satisfactory solution. I have complained that they should shift my support to any other region because I don't need Indian support; they are simply pathetic and not up to mark. To improve Barracuda Web Application Firewall, customers should be given ongoing training opportunities regarding the product and its features. I am not familiar with many features that are available, only using those which are necessary for my applications. I believe Barracuda must provide clearer product information or training sessions to make it more user-friendly, as sometimes its interface can be rigid and lacking in helpful resources or user tutorials about its features. For it to get closer to a ten, I think advanced reporting is missing because, as I mentioned earlier, there are many false positive events being recorded. Often, when I analyze these attacks, they turn out to be genuine customers or users interacting with my product, but Barracuda tags them as attackers. Reducing false positives must be a priority.
HameedAhmed - PeerSpot reviewer
Joint Director at PAA
Security threats have been reduced through seamless deployment and strong integration with other tools
I have used Fortinet FortiWeb's integration features. We have easily integrated all of the applications with the product. Most of the applications we are using are in-house built. My technical team is looking after the best features. I have not used it extensively for maybe two and a half years. I have been involved in the installation, but I am not actually using the product. I work with it from time to time but not extensively. I would assess Fortinet FortiWeb's adaptive machine learning and artificial intelligence as having new patches installed regarding artificial intelligence, but when we bought it, I think the learning feature was there. Now they have installed artificial intelligence features through patches. We have a complete portfolio of Fortinet in our organization, including FortiMail, Fortinet FortiWeb, and FortiGate, along with multi-factor authentication. All of the products are from Fortinet. Fortinet tools integrate with each other and work in conjunction. I think Fortinet FortiWeb has helped us meet regulatory compliance because we are not a regulatory organization, but our sister organization is regulatory. We have regulatory compliance with the International Civil Aviation Authority, whose audit teams have checked our data center and these security products, and they are satisfied with us. The question about leveraging Fortinet FortiWeb's automated policy management does not pertain to my domain because I am not so technical, but I am in a management role now. My engineer is more technical than me. I would rate this product an eight point five out of ten.
ST
Senior Cybersecurity Consultant at Cyberoutcome Limited
Strong policies and bot defenses have secured critical APIs and have reduced attack noise
From my research regarding the IAM space that Imperva Application Security Platform is trying to look into, I believe they still need to do a lot of modeling and modification to make sure that also helps. There are several competitors in the IAM space, so Imperva would do well if they can do some basic modeling and modifications from my own personal research and my own experience in the IAM space. Alternatively, they could actually just focus on trying to be stronger in the web application space and the database activity monitoring space.The main reason it is not a perfect ten is regarding support. At times, having to reach the support team takes eight hours to ten hours maximum. There are times when clients could have urgent issues to attend to. The support team could do more by having a faster response rate.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
889,855 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Financial Services Firm
9%
Comms Service Provider
8%
Computer Software Company
8%
Financial Services Firm
12%
Manufacturing Company
9%
Computer Software Company
7%
Marketing Services Firm
6%
Manufacturing Company
9%
Financial Services Firm
9%
Computer Software Company
8%
Comms Service Provider
7%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise8
Large Enterprise11
By reviewers
Company SizeCount
Small Business60
Midsize Enterprise27
Large Enterprise36
By reviewers
Company SizeCount
Small Business87
Midsize Enterprise25
Large Enterprise66
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What is your primary use case for Barracuda Web Application Firewall?
I have been working with Barracuda Web Application Firewall for more than almost three and a half years. Its main use...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
The pricing, setup cost, and licensing for Barracuda Web Application Firewall are reasonable. They are competitive wh...
What needs improvement with Barracuda Web Application Firewall?
The areas where it could be better are in security profiles, where a single service can have only one policy. There i...
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing for Fortinet FortiWeb varies with different models having different prices. It depends on the requirement...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in Fortinet FortiWeb. The team was only from FortiGate itself. They are making new firm...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators o...
 

Comparisons

 

Also Known As

Cloudflare WAF
No data available
FortiWeb Web Application Firewall (WAF)
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about Fortinet, F5, Imperva and others in Web Application Firewall (WAF). Updated: April 2026.
889,855 professionals have used our research since 2012.