Try our new research platform with insights from 80,000+ expert users

Barracuda Web Application Firewall vs HAProxy comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
7th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Barracuda Web Application F...
Ranking in Web Application Firewall (WAF)
17th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
46
Ranking in other categories
No ranking in other categories
HAProxy
Ranking in Web Application Firewall (WAF)
14th
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
47
Ranking in other categories
Application Delivery Controllers (ADC) (3rd), Distributed Denial-of-Service (DDoS) Protection (6th), Bot Management (7th), Service Mesh (2nd)
 

Mindshare comparison

As of February 2026, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 5.6%, down from 6.6% compared to the previous year. The mindshare of Barracuda Web Application Firewall is 2.0%, up from 2.0% compared to the previous year. The mindshare of HAProxy is 2.5%, down from 3.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
Cloudflare Web Application Firewall5.6%
HAProxy2.5%
Barracuda Web Application Firewall2.0%
Other89.9%
Web Application Firewall (WAF)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Shahzad Abid - PeerSpot reviewer
Director Information Technology at College of Physicians & Surgeons Pakistan
Has protected our legacy applications effectively but has required constant manual filtering due to false positives
I assess the effectiveness of the machine learning-driven threat detection in Barracuda Web Application Firewall as sometimes behaving abnormally, often showing me false positive attacks, so I have to fix these attacks from time to time. From a stability point of view, I would definitely rate Barracuda Web Application Firewall a seven out of ten. There is definitely some room for improvement; nothing is perfect in the world. I am not satisfied with the technical support from Barracuda. I am somewhat disappointed with the technical support that I have received so far. Whenever I generate a ticket for my problem, it goes to the Indian support team, and they all the time start with the most junior team member, consuming all my precious time. At the end, I have to close that ticket without any satisfactory solution. I have complained that they should shift my support to any other region because I don't need Indian support; they are simply pathetic and not up to mark. To improve Barracuda Web Application Firewall, customers should be given ongoing training opportunities regarding the product and its features. I am not familiar with many features that are available, only using those which are necessary for my applications. I believe Barracuda must provide clearer product information or training sessions to make it more user-friendly, as sometimes its interface can be rigid and lacking in helpful resources or user tutorials about its features. For it to get closer to a ten, I think advanced reporting is missing because, as I mentioned earlier, there are many false positive events being recorded. Often, when I analyze these attacks, they turn out to be genuine customers or users interacting with my product, but Barracuda tags them as attackers. Reducing false positives must be a priority.
Shrinivas Devarkonda - PeerSpot reviewer
Head of DevOps at TripFactory
Handles high traffic efficiently and simplifies complex routing with rule-based logic
I think HAProxy is good as it stands now, but I believe there could be improvements. gRPC has recently been implemented, which is great, along with TLS 1.2 and 1.3 support, and HTTP 2.0 is also available. However, I'm unsure about the benchmark of those HTTP 2.0 requests on HAProxy. If there were any other protocol with better performance than HTTP 2.0, or perhaps mTLS and other similar features, including that in HAProxy would be really great. For improvements, I think that during setup and configuration, the steps provided are neat and clear. Anyone can easily install and configure it. There are many kernel tuning parameters also available, which is great. For specific improvement, in terms of logging, I think printing the full object of the request may help, or if there's a way to reference two requests, it would be beneficial to find a complete session history from a logged-in customer, as it would help analyze customer and user analytics.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The rate limiting features and customizations in terms of URL match and applying policies are valuable to me."
"The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10."
"The product has a valuable security control functionality."
"Caching is the most valuable feature of Cloudflare Web Application Firewall."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"It is configurable via API."
"The integration of Cloudflare with Cloud Suite is its most valuable feature."
"It is a SaaS solution unlike much of the competition."
"The installation is straightforward."
"The most valuable feature is the rule set."
"The solution's most valuable feature is that it actually protects our website, and it provides all the required security functions."
"The customer service and support from Barracuda have been excellent."
"The solution is user-friendly and easy to set up."
"The most valuable features are the client VPN and content filtering."
"Barracuda Web Application Firewall provides optimized performance, a user-friendly environment, helpful dashboards, and is simple to use."
"I find the solution very stable."
"With centralized SSL termination and automated renewals now in place, that time requirement has dropped to nearly zero hours, translating to dozens of hours saved per year."
"The solution is user-friendly and efficient."
"It solves a problem for me where I can build files, not based on the health of the check, but rather the speed of the check."
"The technical support has been, in one word, perfect. Every time I call, I’m on the phone with a representative within five minutes who is highly skilled and willing to help, whether in the case of critical issues or simple advice."
"It reduced the load on our main load balancers."
"We were able to use HAProxy for round robin with our databases, or for a centralized TCP connection in one host."
"The anti-DDOS PacketShield filtering solution (embedded in the physical appliances) as well as the BGP route injection are great features and heavily used."
"HAProxy potentially has a good return on investment"
 

Cons

"If they add logs history within the Cloudflare offering, that would be a great benefit."
"The notification part could be improved. It's very much connected to Web Application Firewall, rate-limiting, and DDoS protection."
"The accuracy of the Cloudflare Web Application Firewall could be improved by reducing the number of false-negative alerts."
"The user interface is very simple and straightforward, but users need knowledge about DNS to accomplish tasks."
"We have noticed some latency when the call goes through the firewall. That could be improved."
"Their documentation could be better. They don't have documentation that explains everything well. They have documentation for everything you're looking for, but they lack a single piece of documentation to tie everything together. As a new user or beginner, it took us a little bit of time to figure out how to put all these things in place."
"The platform's control features related to real-time authentication and response time need improvement."
"The reporting could be more granular."
"I faced an issue when Barracuda decided not to support Azure Stack Hub anymore, which was a significant issue as we had many customers using it on that platform."
"The platform's pricing needs improvement."
"I think the main area for improvement in this product is learning it, as can be seen when comparing it to the F5 web application firewall. F5 has a very powerful learning phase when you start using your web application firewall against your site. Barracuda has something like this, but not with the same functionality from my point of view."
"Barracuda Web Application Firewall's load balancing feature could be improved."
"I have issues with the load balancing of the solution which is slow. The connection pooling in Barracuda also doesn't work. There is an issue when someone needs access to a site quickly. The issue is with HTTPS services. I am not sure if they have changed all these in the solution’s latest version."
"I have to go to an individual obligation, make changes, and come out, and go to the next obligation and make the same changes. There is no grouping option."
"The solution needs to leverage some additional features to a broader scale of software-defined networks."
"I would suggest that someone implementing this product is knowledgeable in the IT field, and with the network needs. It is complex."
"Sometimes it's challenging to get through the log, and you need a log to understand what is going on. It isn't easy to map the logging with the documentation, and every time I read the log, I have to pull out the documentation to understand what I'm reading."
"I would like to see better search handling, and a user interface, with a complete functional graphical unit"
"The basic clustering is not usable in our very specific setup. The clustering is mainly a configuration replication and is great in a case of active-passive usage. In the case of an active-active (or with more than two nodes) where the configuration is not fully identical, it cannot be used as-is."
"Dynamic update API. More things should be possible to be configured during runtime."
"Maybe HAProxy could be more modular."
"There are three main areas to improve: 1) Make remote management more modern by adding API. 2) Propose a general HA ​solution for HAProxy (no I'm using keepalived for this). 3) Thread option should be a bit more stable."
"The product does not have any new technologies."
"We've changed solutions as it doesn't fit with our current needs."
 

Pricing and Cost Advice

"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"We pay $210 per month for CloudFlare WAF."
"It is not too pricey."
"The solution is expensive."
"It starts at $20 and can easily go up to $200 monthly"
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"The product pricing was competitive for the value it offers regarding security features."
"They have competitive pricing."
"Cost is a bit on the higher side. Big companies can afford it."
"Barracuda costs us $8,000 per year. Barracuda costs $20,000 for a full subscription, when you try to protect multi-site infrastructure, in different geographical zones and for different data centers. If you have only one site, Barracuda will be cheaper."
"The Barracuda Web Application Firewall is quite expensive."
"The product is expensive."
"The pricing is reasonable."
"In my opinion, the product is fairly priced."
"We are using HAProxy as an open-source."
"The product is open source."
"Very good value for the money. One of the simplest licensing schemes in this category of products."
"The licensing fee for the solution is $690 per unit annually."
"Test/lab virtual machines can be installed without a licence. They can't be used for performance testing but otherwise behave like production nodes."
"It is free of cost."
"I use the open-source version of the product. I don't have experience with the licensed version of the solution."
"HAProxy is free software. There are optional paid products (support/appliances)."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
882,606 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
7%
Computer Software Company
11%
Financial Services Firm
9%
Manufacturing Company
7%
Marketing Services Firm
6%
Computer Software Company
15%
Financial Services Firm
11%
Comms Service Provider
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business25
Midsize Enterprise8
Large Enterprise11
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise15
Large Enterprise16
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't really use the rule-based logic feature or utilize the WAF's ability to scale as a cloud-based service. I don...
What is your primary use case for Cloudflare Web Application Firewall?
I'm using Cloudflare Web Application Firewall on all my domains and any client domains I have; I set them up with a C...
What do you like most about Barracuda Web Application Firewall?
It significantly improved our overall web security posture, addressing intrusions and enhancing control over web URLs...
What is your primary use case for Barracuda Web Application Firewall?
I am not using the API protection feature right now because I don't host any APIs through Barracuda Web Application F...
What is your experience regarding pricing and costs for Barracuda Web Application Firewall?
At the time I was acquiring Barracuda Web Application Firewall, I found it costly compared to other products. To over...
Do you recommend HAProxy?
I do recommend HAProxy for more simple applications or for companies with a low budget, since HAProxy is a free, open...
What do you like most about HAProxy?
The solution is effective in managing our traffic.
What is your experience regarding pricing and costs for HAProxy?
Since we used the open-source version, we were not concerned about pricing, setup cost, or licensing.
 

Also Known As

Cloudflare WAF
No data available
HAProxy Community Edition, HAProxy Enterprise Edition, HAPEE
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Oracle, CBS, Pioneer, Hyundai, Publix, Barnes Noble, Calzedonia, Nordstrom, Samsung, Nascar
Booking.com, GitHub, Reddit, StackOverflow, Tumblr, Vimeo, Yelp
Find out what your peers are saying about Barracuda Web Application Firewall vs. HAProxy and other solutions. Updated: February 2026.
882,606 professionals have used our research since 2012.