Sign in Agent Mode
Categories
Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

3 AWS reviews

External reviews

15 reviews
from and

External reviews are not included in the AWS star rating for the product.


    LokeshKumar4

Unified security has strengthened traffic control and has reduced attacks across all layers

  • April 23, 2026
  • Review provided by PeerSpot

What is our primary use case?

My main use case for Barracuda Application Protection involves using seven-layer protections such as application protections, URL filtering, web filtering, traffic filtering, DDoS, and rate limit authentications, along with SSL certificate authentications. For web-based applications, we enabled only the URL filtering.

We recently set up high availability with Barracuda Application Protection by integrating two Barracuda products, a physical box, in an active-passive setup, integrating dual ISP internet connections, and enabling applications along with URL filtering and security policies. That is the main use case.

I provide examples of how we enable URL filtering based on customer requirements, where they want to block some specific sites and open some specific sites that we have enabled, so blocking and enabling applications with it.

How has it helped my organization?

Barracuda Application Protection has positively impacted my organization by managing traffic well. It enhances access security, operational efficiency, and user experience, leading to customer satisfaction. Operational satisfaction and operational efficiency are also improved from a security perspective. It is the one box where we can implement malware protection and block malware, which is a main concern these days.

What is most valuable?

What I understand about Barracuda Application Protection is that it is a single product and single device where we can get all layers of protections, including seven layers, Layer 3, Layer 4, and Layer 7 as well. With one single box, we can get all features, which is excellent. Based on the license, we have enabled DDoS as well. All of the features are very good, and it is good to go.

Among all those features, I found Layer 3 and Layer 4 DDoS and network flooding to be especially helpful as we enabled protections to monitor and manage network bandwidth by preventing attack types such as SYN flood, UDP flood, and ICMP floods. We also enable protections with SYN cookies and real-time protections that are good with this product.

What needs improvement?

Additionally, I can say that deeper API security features such as automation, API discovery, scheme validations, and improved protections for modern environments are needed. The integration flexibility with SIEM products and automation tools could enhance analytic and monitoring incident response workflows.

I believe automation should be incorporated within the product as it is essential in this AI era. There should be capabilities that allow for providing topologies, protocols, interface IPs, and details in a simple diagram to gather and integrate information as per requirements without any physical or personnel intervention. Zero-touch provisioning and improved AI capability should be enhanced so someone unfamiliar with Barracuda Application Protection can still configure with ease.

For how long have I used the solution?

I have used this product very rarely, but definitely one or twice lead project we implemented with Barracuda

What do I think about the stability of the solution?

Barracuda Application Protection is stable, and we are using it without any impacts for seven months.

What do I think about the scalability of the solution?

Barracuda Application Protection has good scalability, and the environment easily adapts to it.

How are customer service and support?

I have interacted with customer support once, and they immediately responded to my email and provided remote assistance to us in a very quick time, resolving the issues efficiently.

Which solution did I use previously and why did I switch?

I implemented Barracuda Application Protection according to our project requirement, switching from high-cost solutions such as Palo Alto and Cisco ASA, which have similar capabilities but are more expensive compared to Barracuda Application Protection.

How was the initial setup?

I do not have specific return on investment metrics to share at this time as I am a technical person and focus on the technical aspects of Barracuda Application Protection, which I can recommend as a good product for future use.

What about the implementation team?

Our company has a partner relationship with this vendor.

What was our ROI?

I do not have specific return on investment metrics to share at this time as I am a technical person and focus on the technical aspects of Barracuda Application Protection, which I can recommend as a good product for future use.

What's my experience with pricing, setup cost, and licensing?

Cost saving is one of the major points observed since this product is less costly compared to others. We observed several measurement improvements after implementing Barracuda Application Protection, where traffic reduced security alerts by approximately 40 to 43 percent. The availability and response times also improved, making it cost-effective and user-friendly.

My experience with pricing, setup cost, and licensing of Barracuda Application Protection is good, although my team does not manage costing. A different procurement team handles that, but overall my experience with licensing and pricing is good.

Which other solutions did I evaluate?

We evaluated other options such as FortiGate and Palo Alto, but based on specific requirements from the client side, we decided to go with Barracuda Application Protection.

What other advice do I have?

I would consider my overall experience to be limited, but I am happy to work with this product. Barracuda Application Protection is a new product for me, and I always try to learn the good opportunities it offers. The product is a strong silent shield in front while preventing bad traffic from being created, keeping applications strong with user flow and trust. I give this review a rating of ten out of ten.


    Bhavesh Vora

Reliable incremental backups have simplified daily protection and rapid ransomware recovery

  • April 16, 2026
  • Review provided by PeerSpot

What is our primary use case?

Barracuda Application Protection is used primarily for end-to-end backup. The incremental backup is a day-to-day process, and it is easy to use for all the servers and the client machine. Barracuda Application Protection is used exclusively for backup purposes, which involves incremental backup in day-to-day operations and easy restoration using Barracuda backup solutions.

What is most valuable?

The best features Barracuda Application Protection offers include easy installation, incremental backup, and daily email reports.

Regarding the easy installation and daily email reports, it is easy to install, and the quick backup allows for a quick restoration for the machine and the servers, making it a fast process.

Barracuda Application Protection protects against ransomware, achieving a 67% protection rate because it is based on a Linux system, reducing the chances of encryption and providing strong ransomware protection.

Barracuda Application Protection has positively impacted my organization as it is used for multiple clients, and I am also backing up the Exchange servers, which frequently experience attacks in customer environments, allowing for quick restoration, even from yesterday or the day before yesterday.

What needs improvement?

There is nothing in Barracuda Application Protection that needs any updates, but improving ransomware protection from 67% to 100% would be beneficial.

Improving the operating system structure, firmware, and overall performance would enhance loading times for devices.

For how long have I used the solution?

Barracuda Application Protection has been used for the last three years.

What do I think about the stability of the solution?

Barracuda Application Protection is stable.

What do I think about the scalability of the solution?

The scalability of Barracuda Application Protection is good, with normal CPU, memory, and overall system utilization.

How are customer service and support?

Customer support for Barracuda Application Protection is good.

Which solution did I use previously and why did I switch?

Before Barracuda Application Protection, I had multiple solutions, and as a system integrator, I provided various options, preferring Barracuda Application Protection as it is easy to use and easy to restore, unlike some other solutions such as Synology.

What was our ROI?

A return on investment has been seen as it is not necessary to take a backup and check customer environments day-to-day. It is easy to use for simply taking a backup without needing more engineers or employees, and it is a one-time setup.

What's my experience with pricing, setup cost, and licensing?

The pricing, setup cost, and licensing for Barracuda Application Protection are not excessive. The licensing and cost are normal for the Barracuda backup appliance.

Which other solutions did I evaluate?

Other options were not evaluated before choosing Barracuda Application Protection.

What other advice do I have?

Quick restoration with Barracuda Application Protection has allowed restoration of backups multiple times, not just once. As a system integrator, I manage multiple customers' requirements for backups.

For others looking into using Barracuda Application Protection, it is easy to use. I rate Barracuda Application Protection an eight out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Vibin Thomas

Centralized protection has improved visibility and security for web applications and APIs

  • April 16, 2026
  • Review from a verified AWS customer

What is our primary use case?

My main use case of Barracuda Application Protection has been around securing internet-facing web applications and APIs, especially from common web attacks, bot traffic, and API-based threats. In my role, I mainly worked on evaluating it from a solution perspective rather than full-scale deployment. We looked at how it can protect applications against the OWASP Top 10 vulnerabilities, handle bot mitigation, and provide visibility into API traffic, which is becoming a major attack surface now. During the evaluation, we focused on how it fits into a typical enterprise environment, for example, protecting customer-facing applications such as login portals, payment gateways, and APIs. We also checked how easy it is to deploy in different models like SaaS or virtual appliance and how it integrates with existing security tools. Another key area we looked at was policy tuning and false positive handling, because in real environments, business traffic should not be impacted. So we analyzed the logging, reporting, and how effectively it identifies malicious versus legitimate traffic. Overall, the use case was to understand how Barracuda Application Protection can act as a centralized web application and API protection layer, especially for organizations looking for a combined WAF plus API security plus bot protection solution.

How has it helped my organization?

During our evaluation, Barracuda Application Protection had a positive impact mainly in terms of improved visibility and better handling of automated attack traffic. One of the key improvements we noticed was identifying and controlling bot-driven traffic, especially on sensitive endpoints like login pages. It helped reduce repeated suspicious requests and gave better control over credential stuffing scenarios through rate-limiting and bot detection. Another positive impact was around centralized visibility. Barracuda Application Protection provided clear insights into incoming traffic, attack patterns, and policy actions, which made it easier to understand what kind of threats applications are exposed to. This is very useful for both security monitoring and decision-making.

We also saw improvement in application-layer security coverage, as it was able to effectively detect and block common OWASP attacks during testing, which increases the overall confidence in protecting public-facing applications. From an operational perspective, Barracuda Application Protection simplified management by combining WAF, API protection, and bot mitigation in one place, reducing the need to handle multiple tools separately. Overall, the main outcomes were better threat visibility, improved protection against automated attacks, and a more streamlined security approach for web applications and APIs.

What is most valuable?

One of the best features of Barracuda Application Protection is its comprehensive security coverage across web applications and APIs in a single platform. Instead of just acting as a traditional WAF, it combines multiple layers of protection, which is very useful in modern environments. First, its WAF capabilities for OWASP Top 10 protection are very strong. It can effectively detect and block common attacks such as SQL injection, cross-site scripting, and other application-layer threats, which are critical for protecting public-facing applications. Another key feature is API security, which is becoming increasingly important. Barracuda Application Protection provides visibility into API traffic, helps identify abnormal behavior, shadow APIs, and misuse, which traditional WAFs struggle with.

Both the bot protection and rate-limiting capabilities are also very valuable, especially for protecting login portals and preventing automated attacks such as credential stuffing and scraping. It helps differentiate between legitimate users and malicious bots based on behavior analysis. Additionally, DDoS protection at the application layer is well-integrated, which helps in handling traffic spikes and ensuring application availability. From an operational perspective, logging, reporting, and visibility are strong points. Barracuda Application Protection provides clear insights into traffic patterns, attack types, and policy actions, which makes troubleshooting and tuning much easier. Lastly, the flexible deployment options such as SaaS, container-based, and virtual appliance make it adaptable to different enterprise environments, whether on-premises or cloud.

What needs improvement?

One area where Barracuda Application Protection can improve is in policy tuning and ease of configuration, especially for complex application and API-heavy environments. During evaluation, the initial setup was straightforward, but fine-tuning policies to avoid false positives required a deeper understanding and manual effort. Another area is advanced analytics and reporting. While Barracuda Application Protection provides good visibility, having a more intuitive dashboard, deeper insights, and easier correlation of events would help security teams in faster decision-making and threat analysis. There is also some scope for improvement in API security visibility, especially around detailed discovery and classification of APIs, as this is becoming a critical area for modern applications. Additionally, documentation and guided workflows could be enhanced to help new users quickly understand best practices for deployment and tuning, particularly for teams that are not very experienced with WAF solutions. Overall, Barracuda Application Protection is strong from a security standpoint, but improvement in usability, analytics, and API-level visibility would make it even more effective and easier to operate.

One additional area for improvement would be around integration with other security tools. While Barracuda Application Protection does support integrations, having more seamless and out-of-the-box integration with SIEM or SOAR platforms would make it easier for organizations to automate workflows and correlate security events across multiple tools. Also from a support and onboarding perspective, enhancing guided support, best practice recommendations, and faster troubleshooting assistance would further improve the overall user experience, especially for teams during the initial deployment and tuning phase. These improvements would make the solution not only strong from a security standpoint but also more effective to operate in complex enterprise environments.

For how long have I used the solution?

I have had a few months of exposure to Barracuda Application Protection, mainly during evaluation and comparison exercises as part of customer discussion and solution assessment.

How was the initial setup?

An important aspect we observed during the evaluation was around integration and tuning challenges, which are quite common with any WAF solution. From an integration perspective, connecting Barracuda Application Protection into an existing environment was relatively straightforward, especially when placing it in front of the application as a reverse proxy. However, the real effort came during the tuning phase. Since login portals and APIs are very sensitive, even small false positives can impact real users. For example, during initial testing, some legitimate login requests were flagged due to strict security policies, especially when there are unusual parameters or headers. So we had to carefully analyze the logs and fine-tune the rules to ensure balance between security and user experience. Another challenge was handling dynamic or API-based traffic where request patterns change frequently. In such cases, proper understanding of application behavior was required before enabling stricter protection.

On the positive side, Barracuda Application Protection provided good visibility through logs and reporting, which helped in identifying why traffic was blocked and made the tuning process easier. Overall, while security capabilities were strong, a key learning was that proper tuning and understanding of application traffic is critical to get the best results without impacting business operations.

What other advice do I have?

In our case, we evaluated Barracuda Application Protection primarily in a public cloud-oriented setup, as most of the applications we were assessing were internet-facing and hosted in cloud environments. However, one of the advantages we noticed is that Barracuda Application Protection supports flexible deployment models, including SaaS, virtual appliance, and container-based options. This makes it suitable not only for cloud but also for hybrid or on-premises environments, depending on the organization's architecture. From an evaluation perspective, the cloud-based deployment felt more straightforward and easier to integrate, especially for quick testing and scalability. At the same time, it is clear that the solution can adapt well to hybrid setups where some applications are still hosted on-premises.

For our evaluation, we used AWS as the cloud provider. Most of the applications we assessed were hosted in AWS, so it made sense to evaluate Barracuda Application Protection in that environment to see how well it integrates and performs in a typical cloud setup. For our evaluation, we primarily used a trial evaluation setup, so it was not a full purchase through the AWS Marketplace. The focus was more on testing the capabilities and integration within our AWS environment.

One additional improvement I noticed during the trial is around the initial onboarding and learning curve. While Barracuda Application Protection is feature-rich, new users may take some time to fully understand policy structure and best practices. More guided onboarding, templates, or pre-configured policies based on common use cases would help accelerate adoption. Another area is real-time alerting and notification. While Barracuda Application Protection provides good visibility through logs and dashboards, having more customizable and proactive alerting mechanisms would help security teams respond faster to critical events without constantly monitoring the dashboard. These are relatively small enhancements, but they would improve overall usability to make the solution more efficient for day-to-day operations.

My advice would be to clearly understand your application architecture and traffic patterns before implementing Barracuda Application Protection. This helps in getting the most value from the solution, especially when it comes to policy tuning and avoiding false positives. I would also recommend starting with a phased approach, initially deploying in monitoring mode, analyzing the traffic, and then gradually moving to blocking policies. This ensures that security is enforced without impacting legitimate users. Another important point is to focus on bot protection and API security as these are key risk areas today, especially for login portals and public-facing applications. Lastly, make sure to plan for integration with your existing security ecosystem such as SIEM or monitoring tools so that you get better visibility and centralized management. Overall, Barracuda Application Protection is a strong solution, but getting the best results depends on proper planning, tuning, and understanding your environment. I would rate this solution an overall eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


    reviewer2808624

Improved SOC visibility has blocked web attacks and supports faster investigations

  • April 06, 2026
  • Review provided by PeerSpot

What is our primary use case?

I work with Barracuda Application Protection as part of SOC monitoring and web application security, which helped me to detect and block web-based attacks such as SQL injection, suspicious requests, and abnormal traffic patterns from a SOC perspective. It also provides good visibility to the web attacks and helps with faster investigation. The pattern is stable and scalable, but I think the UI and fine-tuning policies can be improved overall.

In my current company, for one of the clients which we are using, Barracuda Application Protection was mainly used to protect the web applications and monitor incoming traffic from external sources. From our SOC perspective, I work on analyzing alerts related to suspicious HTTP requests, possible SQL injection, abnormal traffic spikes, and blocking malicious IPs. Whenever the alerts were triggered, we validated whether it was a real attack or a false positive and took appropriate action accordingly.

In one scenario, we observed multiple requests from a single IP that was targeting the login for our client endpoints with unusual parameters. We suspected and started an investigation. Then we saw that Barracuda Application Protection had detected this suspicious behavior and blocked the IP already. On the SOC side, what we did was verify the logs and confirmed it. We even assumed that it might be a brute-force or injection attempt. After that, what we suspected became true, and that helped me in preventing unauthorized access attempts and reducing investigation.

What is most valuable?

The best features of Barracuda Application Protection are that it has good visibility. Log usability is very good, and the support for investigation is also good. These are the main features. One of the best key features I have seen is that it mainly detects and blocks web-based attacks. As I previously mentioned, SQL injection, cross-site scripting, and suspicious HTTP requests are detected in real-time.

The log visibility in Barracuda Application Protection is very useful from the SOC perspective. It provides detailed information such as the source IP address, the request type, what kind of request type was detected, the targeted URL, and the attack type. During investigations, these logs help to understand the pattern of the attack and the intention of the attack, and whether the activity is really malicious or normal activity. It also helps in identifying repeated attacks from the same IP and analyzing the traffic behavior. Overall, the logs make it easier to investigate web-based threats and correlate them with other security alerts in a SIEM solution. It gives detailed logs such as source IP, request details, and attack type, which help in quick investigation and identifying patterns.

Barracuda Application Protection is helping our current organization in a meaningful way by reducing web-based security incidents through blocking malicious traffic before it reaches the application and end-user machines. It improved visibility into the web attacks and made investigation easier for the SOC employees, especially since we could quickly identify suspicious IPs and attack patterns. It also reduces the manual effort since many attacks were automatically detected and blocked, allowing our SOC team to focus more on analysis rather than basic filtering.

What needs improvement?

I have one thing to share about the features. I did not observe any major stability issues. The platform works reliably during monitoring. If I want to tell what needs improvement, policy tuning requires effort. Policy fine-tuning because it requires a lot of effort and time from the employees, such as the senior SOC analyst. For us, it requires a lot of manual effort. Also, sometimes it gives a lot of false positives that also require manual effort. These two main things need improvement.

Another area for improvement is the visualization of the attack data. Barracuda Application Protection has better visualization of attack data, but it can make it even better. It should be very accessible because nowadays, employees from the data engineer team, the network team, or other departments should be able to easily understand it. I personally feel that is how the user interface should be for all applications. The current trending applications should be built with better UI and UX design for better visualization of the attack data. That would be very helpful for SOC analysts as well as other department employees and colleagues.

For how long have I used the solution?

I have been using Barracuda Application Protection for the past one point two years.

What do I think about the stability of the solution?

I did not observe any stability issues with Barracuda Application Protection in the past.

What do I think about the scalability of the solution?

Barracuda Application Protection is scalable and can even handle the traffic for multiple applications. It is a very good solution in the current market.

Which other solutions did I evaluate?

Cloudflare WAF is another tool I have seen. Cloudflare is also more user-friendly and has a strong CDN and DDoS capabilities, and it is easier to use. However, I would still go with Barracuda Application Protection.

What other advice do I have?

Barracuda Application Protection is a very fantastic tool and a very good solution, especially when talking about web application attacks, particularly from external attacks. Currently in the market, there are very few solutions, and few solution providers are there, but comparatively, they are the best. That is why I rate Barracuda Application Protection eight out of ten.

For example, in day-to-day work, I have observed a repeated request pattern from a particular IP that was targeting the login endpoints with unusual parameters that I noticed. Barracuda Application Protection already detected that suspicious activity and gave notifications on our SIEM solution as well. It even blocked that IP automatically on a temporary basis. We have set up and fine-tuned our SIEM solution so that if any such IPs are detected, they need to be blocked for one to two days because we are not sure about the IP's reputation. With fine-tuning, we have it set to block for two days. That is how we did it. That helped us quickly validate the alert, and we confirmed the potential attack and avoided further impact. It also reduces the manual effort, as many such threats have been handled automatically.

Barracuda Application Protection is a good solution for protecting the web application from external attacks. From my SOC perspective, it provides good visibility to the SOC analyst, and the logs it generates are very comprehensive. That helps us with the investigation and correlating all such logs to the SIEM solution and other things. In our organization, we have a public-facing application, so that is where I can tell this will provide the best benefit from this solution. Compared to other perspectives, Barracuda Application Protection is a very good one, and from my experience, I am really impressed with it. I would rate Barracuda Application Protection eight out of ten.


    Mahesh Konda

Advanced threat protection has reduced zero-day risks but usability and response time still need work

  • April 05, 2026
  • Review from a verified AWS customer

What is our primary use case?

My main use case for Barracuda Application Protection encompasses most of their capabilities. I have used it for APIs, protecting applications, and securing applications for these types of instances.

What is most valuable?

Barracuda Application Protection's best features are protecting APIs and defending against zero-day vulnerabilities.

Barracuda Application Protection has been effective at handling zero-day vulnerabilities for me, and it has caught specific threats. There were several times when Barracuda Application Protection triggered alerts, and I ensured that those threats were addressed before any vulnerability occurred.

Barracuda Application Protection has positively impacted my organization by reducing security impact and threat impact. It has helped me as an architect understand what the threat is, what the analysis shows, and it resolves immediately. That is a best use case scenario, and I would recommend this for everyone.

What needs improvement?

I believe Barracuda Application Protection could be significantly improved with better usability and integration with other tools.

Barracuda Application Protection's WAF serves as a primary defense, but I believe it can be improved. The response time is slow, and the WAF is something that adds more value to that aspect. I would also recommend improving API integration with the API layers and CDN networks, along with the response time of the application, as these need considerable improvement.

For how long have I used the solution?

I have been using Barracuda Application Protection for more than a year and a half.

What do I think about the stability of the solution?

Barracuda Application Protection is stable in my organization.

What do I think about the scalability of the solution?

I was not implementing a complete solution and was only deploying it on a few services. Because of that limited implementation, I did not implement a fully scalable application, which is why it was performing stable.

Which solution did I use previously and why did I switch?

I previously tested between Qualys, Qualys scan, Aqua scan, and Barracuda. Each has its own pros and cons, but I feel that Qualys, Aqua Securities, and Barracuda are at the same level, and I think Barracuda is the winner.

Before choosing Barracuda Application Protection, I evaluated between Aqua scan and Barracuda, and Barracuda proved to be the winner.

What was our ROI?

I have not noticed a return on investment. I was testing this out, and I am not sure how much this constituted a return on investment.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that I feel it is a bit costlier, but the features that it provides are good. However, I am not the one making decisions on costing and limiting, as that is at the organizational level. I am satisfied, and even management shares the same concerns. We have other applications or open-source tools that are not as good as Barracuda, but we could manage with those, so I feel the pricing is too high.

What other advice do I have?

I can share a specific outcome where Barracuda Application Protection was helpful. There was a use case where an e-commerce platform was under a credential attack where attackers were hammering endpoints with millions of requests using leaked credentials. Barracuda Application Protection triggered an alert for abnormal activity using machine learning and implemented rate-limiting and IP blocking based on reputation. It also prevented account takeovers by rate-limiting the number of user requests. That was an instance where I could see how helpful Barracuda Application Protection was.

The main advice I would give to others considering Barracuda Application Protection is that it stands out with its zero-day vulnerability protection, which is excellent. It performs very well with threat detection and finding anomalies, and it is effective at preventing DDoS attacks, which are common in the data centers of any organization. My only concerns are that it is not very user-friendly and the response time is slow. I would rate this product a seven out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


    Mohak Christine

Secure gateway has strengthened mobile access and consistently reduced web security incidents

  • February 15, 2026
  • Review from a verified AWS customer

What is our primary use case?

My main use case for Barracuda Application Protection is for our mobile apps and for the remote users we have, as I use this as the secure gateway to protect the application integrity as well as the data going from our organization to our users remotely as well as the ones in-house.

What is most valuable?

Barracuda Application Protection specifically helps with securing our mobile apps and remote users by providing full-spectrum security DOD-level protection, which is a big help for us for the security of our data. Implementing Barracuda Application Protection has had a measurable and strategic impact on our overall business objectives. Within the first six to seven months of deployment, I saw a 60% reduction in security incidents, incidents affecting the web application which directly translated into fewer service interruptions and less time spent on incident response.

Overall, Barracuda Application Protection has made it so easy to manage all our applications.

The best features Barracuda Application Protection offers include ease of setup on a firewall for security for VPN users, and configuration is easy to do and use for our security team with its features and pictures of instruction. Additionally, ease of deployment, less costly, easy to manage application, scalability is good, and security features are strong. It contains a lot of granularity, especially with URL profiles, protection, and JSON security.

Granular controls and JSON security have helped our team by providing a secure gateway to protect application integrity as well as the data going from our organization to the users remotely, as well as the ones in the offices.

I would also add that it has been good in lessening threats from the outside, and being able to set as many rules as needed is a big plus for us.

What needs improvement?

I do not have much to say about the improvement, but a more innovative solution for sniffing more on the network would be great, and having the advanced ability to close off ports when they could be getting tested from hackers for intrusion would be helpful.

I would also add that the user interface should be improved to be more user-friendly and customizable.

For how long have I used the solution?

I have been using Barracuda Application Protection for five years.

What do I think about the stability of the solution?

Barracuda Application Protection is fast and reliable, so it is very stable.

What do I think about the scalability of the solution?

Barracuda Application Protection's scalability is very good; it handles my organization's growth perfectly.

How are customer service and support?

The customer support is quick to respond and very solution-oriented.

Which solution did I use previously and why did I switch?

Previously, I was using Cloudflare.

I decided to switch from Cloudflare to Barracuda Application Protection because it is very easy to use, the cost is very cost-effective, it has simplicity to configure and deploy in my current environment, and it has automated standard policies, which is easy to maintain.

What was our ROI?

I have seen a return on investment; it lessens threats from the outside. Ease of use for our security team to be able to use templates and configure to our specs, combined with its high-level security protection features such as DOD-level protection, shows its readiness to secure our data and network lines, which is brilliant.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that it is a very cost-effective tool.

Which other solutions did I evaluate?

Before choosing Barracuda Application Protection, I evaluated other options including AWS WAF.

What other advice do I have?

My advice to others looking into using Barracuda Application Protection is that it is simple, very simple, cost-effective, easy to set up and use, and easy to configure and deploy in any environment. It lessens threats from outside or from within.

I have additional thoughts about Barracuda Application Protection; it is a good tool for providing threat protection, especially for our email that comes in from the outside. Capturing potential spam and malware from emails from outside our network has been good, keeping us alert for anything coming in from the outside that could compromise our network.

I rate this product a 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    TarunKumar7

Advanced protection has reduced web threats and now keeps our remote users and data secure

  • December 07, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for Barracuda Application Protection is that it is a very exceptional piece of security in a virtual and remote world. It provides full-spectrum security DOD-level protection, which is a big help for us for the security of our data. It also provides ease of setup on the firewall for security for all our VPN users. Additionally, configuration is easy to do and use for our security team, which benefits from its features and instructional pictures.

What is most valuable?

The best features that Barracuda Application Protection offers are DOD-level protection and its readiness to secure our data and network lines. Built-in templates are easy to use and good to customize to make them work how we do things. Overall, it keeps us alert for anything coming in from the outside that could compromise our network.

Barracuda Application Protection has positively impacted my organization by lessening threats from outside. The ease of use for our security team to be able to use templates and configure to our own specs has also been a benefit. Being able to set as many rules as you like is also a big advantage to our side.

What needs improvement?

Barracuda Application Protection could be improved with a more user-friendly interface to enable all types of people to be able to use it, especially the less technical users. More support categories should be integrated.

For how long have I used the solution?

I have been using Barracuda Application Protection for three years.

What do I think about the stability of the solution?

I find Barracuda Application Protection to be very stable.

What do I think about the scalability of the solution?

Barracuda Application Protection is very scalable. It grows with our needs in my organization.

How are customer service and support?

The customer support for Barracuda Application Protection has been very responsive and helpful in resolving all our issues on time. My user experience with them has been great and phenomenal.

Which solution did I use previously and why did I switch?

I previously used the Palo Alto Networks Next-Generation Firewalls PA-Series before switching to Barracuda Application Protection.

What was our ROI?

I have seen a return on investment from Barracuda Application Protection. Implementing it has had a measurable and strategic impact on our overall business objective. Within the first six months of deployment, we have seen a 60% reduction in security incidents affecting the web application, which directly translated into fewer service interruptions and less time spent on incident response.

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing, setup cost, and licensing is that the setup was straightforward and easy with no hassle. The cost is relevant, pocket-friendly, and cost-effective.

Which other solutions did I evaluate?

Before choosing Barracuda Application Protection, I evaluated other options like HP and Juniper Access Points.

What other advice do I have?

My advice to others looking into using Barracuda Application Protection is that it is a great tool to have in your organization to prevent attacks from outside. It is a great tool that helps in bot identification and protecting all our applications in any organization. It is also cost-effective to provide zero-day vulnerabilities.

Barracuda Application Protection is the next-generation tool to protect all our organization apps and is very cost-effective.

I found this interview to be straightforward, very easy, and overall, great. I would rate this review a 9.


    Shivam M.

Best Web application firewall service from Barracuda

  • February 07, 2023
  • Review provided by G2

What do you like best about the product?
Easy integration and deployment, Able to work well as a layer 7 network protection device, Custom filtering rules are supported which brings WAf to advance level.
What do you dislike about the product?
Doesn't support SSL offloading, Reporting and dashboard can be improved further, Support services SLA should be improved. Device capabilities can be improved further.
What problems is the product solving and how is that benefiting you?
It is helping us in protecting our web application with OWASP top 3.2 top rules, we able to detect and prevent most of external attack using Barracuda WAF. This improved our business application performance as well as revenue.


    Information Technology and Services

Great way to protect web applications via an as-a-service platform

  • January 20, 2023
  • Review provided by G2

What do you like best about the product?
Barracuda WAF-as-a-Service offers a complete package as you would expect from a WAF, but everything is SaaS-based. The WAF-as-a-Service offers very detailed configuration possibilities.
What do you dislike about the product?
Sometimes it is difficult to configure the WAF to be fully proof. It takes some time before all the false positives are gone. But this is the case with every WAF.
What problems is the product solving and how is that benefiting you?
We use the WAF-as-a-Service to protect all our public facing web applications. In the past we had to install a WAF on premise but now everything is updated and maintained in the cloud


    Nitin P.

It good but there are better options available

  • January 04, 2023
  • Review provided by G2

What do you like best about the product?
It's ML algo is really great it's able to detect existing bugs in the bot...it's just like a human debugging the code...upside is the package that they offer irresistible...
What do you dislike about the product?
Thhe updates which the barracuda people provide are really slow...they do not release updates that frequently....bots in today's time are evolving fast so should the bot error detection tools
What problems is the product solving and how is that benefiting you?
It helped me get over the mundane task of debugging....i didn't had to allocate my resource to just debug the basic code as well...company is benefitted from this...