Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs HAProxy comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Barracuda Web Application F...
Ranking in Web Application Firewall (WAF)
17th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
45
Ranking in other categories
No ranking in other categories
HAProxy
Ranking in Web Application Firewall (WAF)
14th
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
47
Ranking in other categories
Application Delivery Controllers (ADC) (3rd), Distributed Denial-of-Service (DDoS) Protection (6th), Bot Management (7th), Service Mesh (2nd)
 

Mindshare comparison

As of January 2026, in the Web Application Firewall (WAF) category, the mindshare of Barracuda Web Application Firewall is 2.1%, up from 2.0% compared to the previous year. The mindshare of HAProxy is 2.6%, down from 3.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
HAProxy2.6%
Barracuda Web Application Firewall2.1%
Other95.3%
Web Application Firewall (WAF)
 

Featured Reviews

Shahzad Abid - PeerSpot reviewer
Director Information Technology at College of Physicians & Surgeons Pakistan
Has protected our legacy applications effectively but has required constant manual filtering due to false positives
I assess the effectiveness of the machine learning-driven threat detection in Barracuda Web Application Firewall as sometimes behaving abnormally, often showing me false positive attacks, so I have to fix these attacks from time to time. From a stability point of view, I would definitely rate Barracuda Web Application Firewall a seven out of ten. There is definitely some room for improvement; nothing is perfect in the world. I am not satisfied with the technical support from Barracuda. I am somewhat disappointed with the technical support that I have received so far. Whenever I generate a ticket for my problem, it goes to the Indian support team, and they all the time start with the most junior team member, consuming all my precious time. At the end, I have to close that ticket without any satisfactory solution. I have complained that they should shift my support to any other region because I don't need Indian support; they are simply pathetic and not up to mark. To improve Barracuda Web Application Firewall, customers should be given ongoing training opportunities regarding the product and its features. I am not familiar with many features that are available, only using those which are necessary for my applications. I believe Barracuda must provide clearer product information or training sessions to make it more user-friendly, as sometimes its interface can be rigid and lacking in helpful resources or user tutorials about its features. For it to get closer to a ten, I think advanced reporting is missing because, as I mentioned earlier, there are many false positive events being recorded. Often, when I analyze these attacks, they turn out to be genuine customers or users interacting with my product, but Barracuda tags them as attackers. Reducing false positives must be a priority.
Shrinivas Devarkonda - PeerSpot reviewer
Head of DevOps at TripFactory
Handles high traffic efficiently and simplifies complex routing with rule-based logic
I think HAProxy is good as it stands now, but I believe there could be improvements. gRPC has recently been implemented, which is great, along with TLS 1.2 and 1.3 support, and HTTP 2.0 is also available. However, I'm unsure about the benchmark of those HTTP 2.0 requests on HAProxy. If there were any other protocol with better performance than HTTP 2.0, or perhaps mTLS and other similar features, including that in HAProxy would be really great. For improvements, I think that during setup and configuration, the steps provided are neat and clear. Anyone can easily install and configure it. There are many kernel tuning parameters also available, which is great. For specific improvement, in terms of logging, I think printing the full object of the request may help, or if there's a way to reference two requests, it would be beneficial to find a complete session history from a logged-in customer, as it would help analyze customer and user analytics.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution has been quite stable. It's reliable."
"Our customers value the solution's simplicity."
"There is no one special feature, but the WAF itself is valuable: user-friendly protection against web attacks etc., authentication, reporting, accountability, alerting, and hardened OS."
"The product's advanced bot and threat protection capabilities are valuable."
"This product gives us visibility into what is going on in two servers, including connections and sessions, real-time alerts, very good reporting, and KPIs. It makes managing security of a critical server very easy, with a friendly GUI."
"Since implementing Barracuda, I sleep smoothly knowing I have protection."
"It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment."
"We use Barracuda to protect the application. That's the main feature we use it for."
"What I like best about the product is its simplicity and speed. When you need to set up a load balancer quickly, HAProxy offers options like sticky sessions and round-robin. It's also fast to configure, including adding SSL for security. While it may have fewer options than other solutions like F5, HAProxy gets the job done for basic load-balancing tasks."
"The features I find valuable in this solution are session control which automatically disconnects users that forget to log off, and the ability to write rules to either allow or block certain file requests."
"The most valuable thing for me is TCP/IP Layer 4 stuff you can do with HAProxy. You can go down to the protocol level and make decisions on something."
"I can't speak to all of the HAProxy features because we don't use them all, but load balancing is very good."
"The support for all major Linux distros makes running and testing a breeze."
"We did not need technical support because the documentation is good."
"The solution is effective in managing our traffic."
"​It has allowed us to evenly distribute the load across a number of servers, and check their health and automatically react to errors."
 

Cons

"The incident reporting needs to be improved."
"We get false positives about phishing emails."
"Barracuda Web Application Firewall's load balancing feature could be improved."
"This product could easily progress to be among the industry leaders. I think they need to improve enterprise level automation. It integrates with a small number of vulnerability scanners, so report results should be imported manually; same for SIEM integration."
"I think the main area for improvement in this product is learning it, as can be seen when comparing it to the F5 web application firewall. F5 has a very powerful learning phase when you start using your web application firewall against your site. Barracuda has something like this, but not with the same functionality from my point of view."
"There's potential for improvement in the platform's CMS integration."
"An area for improvement in Barracuda Web Application Firewall is attack identification. Other banks identified attacks and tracked logs that the solution wasn't able to identify because of its ready-made rules pre-deployed by the vendor. My organization raised this issue with the technical support team. Another area to improve in Barracuda Web Application Firewall is its service desk. The team resorted to stonewalling because they couldn't accept that a feature was missing in the solution, and it was only after a lot of drilling down that the service desk team accepted that, and would be adding that feature in the future. My organization had to submit a report to the Reserve Bank of India with information on the logs identified and the attacks that happened, and that there was a failure on the part of the Barracuda Web Application Firewall. The Reserve Bank of India conducts a tri-monthly cyber risk audit in all Indian banks. Even smaller banks identified and caught attacks that my organization wasn't able to do, so I was looking into other solutions that competitor banks could be using because Barracuda Web Application Firewall failed to identify some of the attacks."
"The usability of the interface could be improved."
"There are three main areas to improve: 1) Make remote management more modern by adding API. 2) Propose a general HA ​solution for HAProxy (no I'm using keepalived for this). 3) Thread option should be a bit more stable."
"They should introduce one feature that I know many people, including me, are waiting for: HAProxy should have provide hot-swipe for back-end servers. Also, they need a more detailed GUI for monitoring and configuration."
"There is no standardized document available. So, any individual has to work from scratch to work it out. If some standard deployment details are available, it would be helpful for people while deploying it. There should be more documentation on the standard deployment."
"I would like to see better search handling, and a user interface, with a complete functional graphical unit"
"While troubleshooting, we are having some difficulties. There are no issues when it is running; it is stable and very good; however, if there is a troubleshooting issue or an incident occurs, we will have issues because this is open-source."
"We need to handle new connections by dropping, or queuing them while the HAProxy restarts, and because HAProxy does not handle split config files."
"Dynamic update API. More things should be possible to be configured during runtime."
"​It needs proper HTTP/2 support.​"
 

Pricing and Cost Advice

"The product is inexpensive."
"While I would have to check on the price of the solution, I feel it to be okay and it matches the market price."
"The solution is based on a licensing model and might be $360 for the hybrid version."
"The Barracuda Web Application Firewall is quite expensive."
"They only offer a yearly licensing plan."
"The product pricing was competitive for the value it offers regarding security features."
"The price of this solution is okay."
"For small companies, the price is very expensive because the WAF is an enterprise-level application, not intended for smaller businesses. In my opinion, the price is right for enterprise-level use."
"It is free of cost."
"HAProxy is an open-source solution."
"If you don't have expertise then go with the licensed version. Otherwise, open-source is the best solution."
"Test/lab virtual machines can be installed without a licence. They can't be used for performance testing but otherwise behave like production nodes."
"We use NGINX as well. However, because the health checks are a paid feature, I like to avoid it whenever possible​."
"The price is well worth it. HAProxy Enterprise Edition paid for itself within months, simply due to the resiliency it brings. It was a bit more expensive than we were originally interested in paying, but we are thankful we chose to go with HAProxy."
"HAProxy is free open-source software."
"The tool is open-source."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
880,901 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
University
7%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
11%
Comms Service Provider
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business25
Midsize Enterprise7
Large Enterprise11
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise15
Large Enterprise16
 

Questions from the Community

What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs in our environment.
What is your primary use case for Barracuda Web Application Firewall?
I am not using the API protection feature right now because I don't host any APIs through Barracuda Web Application Firewall. I use a second procedure for API, which is point-to-point VPN connectiv...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
At the time I was acquiring Barracuda Web Application Firewall, I found it costly compared to other products. To overcome that price factor, I excluded some features or subscriptions to align with ...
Do you recommend HAProxy?
I do recommend HAProxy for more simple applications or for companies with a low budget, since HAProxy is a free, open-source product. HAProxy is also a good choice for someone looking for a stable ...
What do you like most about HAProxy?
The solution is effective in managing our traffic.
What is your experience regarding pricing and costs for HAProxy?
Since we used the open-source version, we were not concerned about pricing, setup cost, or licensing.
 

Also Known As

No data available
HAProxy Community Edition, HAProxy Enterprise Edition, HAPEE
 

Overview

 

Sample Customers

Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Booking.com, GitHub, Reddit, StackOverflow, Tumblr, Vimeo, Yelp
Find out what your peers are saying about Barracuda Web Application Firewall vs. HAProxy and other solutions. Updated: December 2025.
880,901 professionals have used our research since 2012.