Overview
A leader in cloud security and an AWS Preferred Security Competency Partner, businesses trust Barracuda's Cloud Generation Firewalls to secure their applications in the cloud. With dynamic profiling and application-aware technologies to minimize false positives, Barracuda CloudGen WAF protects against today's advanced, persistent and zero-day threats.
Trusted by the world's most security-conscious businesses, including financial institutions, government agencies and trading platforms; the Barracuda CloudGen WAF inspects all bi-directional web traffic, and guards against data loss by inspecting the HTTP responses from the back-end servers. Built-in access controls enable administrators to create granular policies for Authentication, Authorization & Accounting (AAA).
Support for CloudFormation Templates enables admins and devops to automatically bootstrap and cluster additional instances as needed, for higher throughput and easy deployment. Active DDoS Prevention stops volumetric and application DDoS attacks before they reach your firewall. The built-in Barracuda Vulnerability Remediation Service removes much of the administrative overhead associated with firewall maintenance by automatically configuring the firewall based on vulnerabilities found in a scan of your application.
How secure are your web applications?
NOTE: Only AMIs with version 10.x or higher version support the Elastic Network Adapters (ENA).
Highlights
- Detects and blocks SQL injections, cross-site scripting, malware uploads, application DDoS, or any other attacks against your application. Authentication and access control gives organizations strong authentication and user control.
- Scans outbound traffic to detect sensitive data, and can either mask or block the information from being leaked out.
- Application acceleration capabilities, including caching, compression, and connection pooling for faster application delivery of web application content.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Please see Barracuda's website.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
- By default, the Barracuda WAF listens on port 8000 for HTTP and port 443 for HTTPS, so make sure these ports are added in the Inbound Rule of the security group that will be associated with the Barracuda Web Application Firewall.
- Allow a few minutes before taking any further actions in the EC2 Portal after deploying the Barracuda Web Application Firewall. During this time, the Amazon Web Services Agent and the Barracuda WAF are booting.
- Now access the Barracuda Web Application Firewall using the associated Public IP/Public DNS with port 8000 over HTTP (i.e. http://<public IP>:8000)
- You will then see the Licensing page which displays the options 'I Already Have a License Token', 'I Would Like to Purchase a License', and 'I Would Like to Request a Free Evaluation'. Select the desired option, fill in the required info, and click 'Provision/Submit'. The Barracuda Web Application Firewall will connect to the Barracuda Networks servers to fetch the required information based on your license, after which the system will start the provisioning process. Once complete, you will be presented with the web administration login page. Log in as the user 'admin' to begin configurations. Your initial password is the EC2 instance ID, and can be changed when configuring your Barracuda Web Application Firewall.
For the Deployment Guide and other instructions, visit the Barracuda campus at https://campus.barracuda.com/product/webapplicationfirewall/article/WAF/AWS/
Support
Vendor support
Support Hours: Basic Support Hours: 8:00 AM - 5:00 PM PST, Monday through Friday. Email and Phone Support offered 24x7 without any phone trees. You will actually speak to a live person. Please have your AWS Account ID available when you contact Barracuda Support; it is required for the support technician to assist you North America - 408 342 5300 Europe - +44 (0) 1256 300 102 Australia - +612 8019 7254 China - +86 400 720 8200 Japan - +81 3 5436 6236 India - +91 804 904 8600 Germany, Austria, Switzerland - +43 (0) 508 100 800 Support Website: https://www.barracuda.com/support -- Support Email: support@barracuda.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Centralized console has improved real-time protection and prevents unauthorized remote access
What is our primary use case?
My main use case for Barracuda CloudGen Firewall is protection and preventing unauthorized access.
A specific example of how I use Barracuda CloudGen Firewall for protection and preventing unauthorized access involves contractors and subcontractors who require access to the main console. They mostly log in remotely, and each time it creates a new login. I maintain a list of verified, safe devices that I input into the system. If someone tries to log in with unauthorized devices, it automatically gets blocked. On my console, a pop-up question asks if this device can be verified for access. Most of the time, I have to physically call the contractor or subcontractor office and ask for the device ID before allowing them to log in. In the past, we had a few breaches, but we were able to rectify the situation in a timely manner. With Barracuda CloudGen Firewall, it is much easier because the question pops up on my console asking me to grant access or not.
Day-to-day, my use of Barracuda CloudGen Firewall is primarily protection, and I am able to watch incoming and outgoing traffic. Due to changes in upgrades and updates of hardware and software, I sometimes need to dynamically plug some ports. It is very easy to do with Barracuda CloudGen Firewall because I see everything on one console, enabling me to do it across the network in real time.
What is most valuable?
The best features Barracuda CloudGen Firewall offers include a centralized console where I am able to see all incoming and outgoing traffic as well as the size of the packets. By the size, I can easily see what is occurring. If someone has copied a device ID and credentials, by the size of the outgoing packets of information, I can easily determine if it should be allowed and automatically block the access in real time without worrying. I do not have to call back and forth for verification; I can just automatically block and stop all activities in real time to prevent unauthorized access. Because I see it on the main console, it is very easy to understand and analyze what is happening. Everything happens in real time without waiting or asking questions. As long as the rules are followed, everything is fine. If any rules are not properly followed, the system alerts me and automatically blocks access even before I click to block access. I do not have to worry because it shifts responsibility from me to Barracuda CloudGen Firewall since it is doing everything in real time to prevent unauthorized access or leakage of information if any device has been compromised or has stolen credentials used to log in.
The most important aspect of Barracuda CloudGen Firewall for me is its easy integration into the system. I do not have to jump through hoops. The integration is done in real time, and after upgrades and updates, it continues integrating without me needing to do much. Everything happens automatically, which saves lots of time and money ultimately, making it easy to operate and see.
Barracuda CloudGen Firewall has positively impacted my organization by saving us lots of time and man-hours, ultimately saving us lots of money. It is very efficient and offers a very high level of security. We have beefed up our security with Barracuda CloudGen Firewall, and I am able to see everything on one main console in real time without jumping around because Barracuda CloudGen Firewall does it for me. If any rules are not followed, Barracuda CloudGen Firewall blocks the traffic or user, and I just need to click one more time to deny access and remove an unauthorized user from the system.
What needs improvement?
To improve Barracuda CloudGen Firewall, I would like to receive worldwide updates of security breaches on the Barracuda CloudGen Firewall console, informing me of events such as something happening in Singapore and detailing how unauthorized access occurred so I can be aware and alert.
For needed improvements, I would like to see better, brighter color alerts on the console that say "Warning, warning, warning." It would also be nice to get a louder warning type. Additionally, I would appreciate an option when I connect some of my approved devices, such as an Apple Watch, for the warning to pop up on my Apple Watch saying "Warning, unauthorized access, unauthorized user, be aware." This way, if I am not at the console but somewhere in the office, I could return to the console and check the problem easily.
For how long have I used the solution?
I have been using Barracuda CloudGen Firewall for at least a year and a half.
What do I think about the stability of the solution?
Barracuda CloudGen Firewall is generally stable. I have experienced reliability issues sometimes after an update of the AI engine, but these issues are very temporary and minor.
What do I think about the scalability of the solution?
The scalability of Barracuda CloudGen Firewall is excellent. It can handle growth in traffic and users easily, particularly since we have acquired new companies, and we have been able to easily update and upgrade the license, which shows great scalability.
How are customer service and support?
Customer support for Barracuda CloudGen Firewall is timely and responsive. When needed, it can easily be changed from tier one to tier two for more advanced support. There were no problems that were not resolved to our satisfaction.
Which solution did I use previously and why did I switch?
I previously used Kaspersky, but because of security breaches and the fact that it originated from a Russian company, we decided not to trust it anymore. We were looking for different solutions when we came across Barracuda CloudGen Firewall.
What was our ROI?
Since using Barracuda CloudGen Firewall, the security incidents have decreased significantly by approximately 25 to 35 percent across our global network. Before, we used to spend at least five hours after upgrades and updates to integrate everything back. Now, we save five to ten hours of man-hours that would have been wasted on integration because it happens automatically on my console. It has saved me at least ten hours of man-hours that would have been necessary for sending technicians on-site to verify the handshake and the install, making sure everything is correct.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Barracuda CloudGen Firewall started with trying it on a sandbox. After which the pricing was approved by our accounting department and chief financial officer. Once approved, we implemented it, and compared to other solutions, it is fairly priced. Our higher-ups are happy with that.
Which other solutions did I evaluate?
Before choosing Barracuda CloudGen Firewall, I evaluated other options, specifically Nortel and Cisco Security.
What other advice do I have?
My advice for others considering Barracuda CloudGen Firewall is to get a trial, set it up in a sandbox, see how well it performs in your environment, and if you find it suitable, use it. Barracuda CloudGen Firewall is a good, reliable solution.
I think Barracuda CloudGen Firewall is a good, reliable, robust solution. I appreciate it because I am able to see everything in real time on one console without jumping through too many hoops.
Regarding Barracuda CloudGen Firewall's AI capabilities, I think it has good governance and security, but the AI needs to be smarter or have a better engine. It needs to be more advanced and predictive, performing preemptive strikes by blocking the port that an unauthorized device is trying to access even before it attempts to log in to the system.
Mostly, Barracuda CloudGen Firewall's AI has made correct decisions for me, but I would appreciate it to pick up the IP addresses of compromised devices and create an updated list in real time. If it could gather information from our security providers through the shared information log, it could notify me if a device with a specific IP address has been flagged as compromised. I would rate this product an 8 out of 10.
Integrated threat protection has secured remote access and now needs smoother monitoring integration
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
I do get a lot of use cases to contact the technical support. One is starting from the integration standpoint and starting from the initial deployment standpoint. The deployment strategy was quite complicated considering the nature of deployment strategy that we have chosen. During the integration phases, we do contact their technical support.
I'll rate the technical support at an average of seven. The reason is they are good at certain phases of the support, and not at certain phases of the support. When I say certain phases of the support, when you are buying the product and when you are deploying at the initial phase, they are quite supportive because they wanted to establish their mark in the organization. But once everything is done and once when we are trying to configure the use cases or probably the integration phase with other tools, the support we expect at that phase of the project is not bad, but quite average. There might be a lot of reasons behind it as well. I do understand that because the kind of customer service that we would have adopted, there are a lot of customer service options available, such as gold or silver. Probably the option that we have chosen as an organization might not be better. I am not sure. But during the integration phase, I would say it is quite average. On a scale of ten, I rate it seven.
How was the initial setup?
Which other solutions did I evaluate?
What other advice do I have?
Improved hybrid connectivity and centralized control have supported branch networks but need simpler UI and stronger AI security
What is our primary use case?
Barracuda CloudGen Firewall is for cloud security because cloud service providers like Azure , AWS , and GCP provide interfaces where organizations need to install different firewalls to secure their infrastructure. The normal security gateway or three-layer firewall they offer is not sufficient to control current threats. Barracuda CloudGen Firewall can protect infrastructure from Layer 7 aspects.
Barracuda CloudGen Firewall is designed for organizations with multiple branches and hybrid cloud environments. It provides strong SD-WAN capabilities including intelligent routing, failover, and link optimization. For example, if a company has offices in different locations such as Pune, Bangalore, and the US, and the MPLS link fails, the firewall automatically switches traffic to broadband without any downtime. Additionally, connecting AWS VPC to on-premises networks is straightforward and secure.
What is most valuable?
The support for distributed and hybrid environments is the best aspect I appreciate about Barracuda CloudGen Firewall. It provides strong SD-WAN capabilities including intelligent routing, failover, and link optimization. If a company has offices in different locations such as Pune, Bangalore, and the US, and the MPLS link fails, the firewall automatically switches traffic to broadband without any downtime. Connecting AWS VPC to on-premises networks is straightforward and secure.
Another valuable feature is easy centralized management. From one single console, I can manage multiple firewall policies, rules, and updates very easily. From a security coverage perspective, it provides good security coverage including firewalling, IPS, VPN, web filtering, and malware protection. The most important aspect is that while enabling these features, it works in real life and functions very well according to the defined policy.
For mid-size and small-size organizations, a cost-effective solution is the fourth and most important point. If I were to buy a similar solution from competitors such as Palo Alto, Cisco, or Check Point, they offer this solution at a higher cost. Where cost is a concern for an organization, Barracuda CloudGen Firewall is a good choice.
Strong hybrid SD-WAN capabilities are the best feature I have seen. The availability has increased significantly due to good SD-WAN capabilities that bring features including intelligent routing, failover, and link optimization. If anything fails in a disaster scenario, the failover is very smooth, so the end user will not realize what exactly happened at the perimeter. Additionally, good link optimization capabilities improve user experience when accessing different public resources. Since we are moving from browser segments to application segments, a good strong link is necessary. From that perspective, it is very much easier to configure link optimization and user experience is excellent.
What needs improvement?
From a user interface perspective, I do not see that much cleanliness compared with other vendors such as Palo Alto and Check Point. While creating policies, some settings are hidden inside multiple menus, which makes it slightly confusing, and a person who has never used Barracuda CloudGen Firewall may need some time to learn that. The user interface and learning curve need to be more simple.
From an advanced threat perspective, AI-driven detection and deep endpoint integration may need some more improvement. Nowadays, to enable advanced threat protection, organizations may require some additional tools for complete protection. That is another improvement area.
From a performance and scaling perspective, I have seen that performance can be impacted when all security features are enabled. That is why I recommend that this solution is not ideal for enterprise-grade environments or organizations. Additionally, from an ecosystem and integration point of view, there is a smaller ecosystem compared to leading firewall vendors. Integration with third-party tools requires additional efforts. For example, integration with SIEM tools such as Splunk works but needs some manual setup. These are the improvement areas for Barracuda CloudGen Firewall in my view.
Nowadays, AI is everywhere, and every solution infuses AI for product portfolio enhancement. However, when we infuse AI, we need to take care of other aspects as well because AI can help us enhance our cybersecurity posture, but at the same time, it can be a nightmare that brings attackers. We need to use caution while enabling any AI-driven features. From an overall rating perspective, I would say it is medium. I do not see anything exceptional with the AI.
For how long have I used the solution?
I have used Barracuda CloudGen Firewall since my TCS days, and I have been using it for almost four to five years.
What do I think about the stability of the solution?
Barracuda CloudGen Firewall is a stable solution. I have not experienced any crashes or downtime. However, when all features are enabled, there are some performance spikes that occur.
What do I think about the scalability of the solution?
I can handle growth and larger workloads easily with Barracuda CloudGen Firewall. I do not see any problem with the scalability aspect.
How are customer service and support?
From a customer support perspective, I would rate it at eight. The knowledge base is also good. Whenever I faced any issues and searched the knowledge base, I found many solutions in place.
Which solution did I use previously and why did I switch?
I have not switched from anything, as I work with various products in my portfolio. I have worked with Barracuda CloudGen Firewall, Fortinet, and Palo Alto, so I have worked with all these leading vendors. As required, I need to work with different vendor solutions. For me, it is about the technology and the firewall. The vendor may be different, and based on the project, I need to work on different tools.
What was our ROI?
From a money saved perspective, it is almost more than fifty percent money saved. Due to its feature set, the user experience also improved by around fifteen to twenty percent.
What's my experience with pricing, setup cost, and licensing?
Although I am not directly involved in that particular segment, from what I understood from the pricing information, it is a very cost-effective solution compared with other well-known firewall vendors that are in the market.
Which other solutions did I evaluate?
I evaluated Fortinet and Palo Alto as solutions.
What other advice do I have?
From a user interface perspective, I do not see that much cleanliness compared with other vendors such as Palo Alto and Check Point. While creating policies, some settings are hidden inside multiple menus, which makes it slightly confusing, and a person who has never used Barracuda CloudGen Firewall may need some time to learn that. My advice to others looking into using Barracuda CloudGen Firewall is that if an organization is mid-size or small-size, it can easily use Barracuda CloudGen Firewall. However, if it is a large or enterprise organization, you must think it through. If an organization is moving into the cloud and has a smaller footprint, Barracuda CloudGen Firewall can be used because in the cloud, organizations are getting a clean pipe solution. It is easy to use it in a cloud environment with minimal application solutions. My overall rating for this product is six.
Security has protected our data centers but support gaps and limited expertise remain challenging
What is our primary use case?
Barracuda CloudGen Firewall is used to protect data in two data centers, including headquarters and data center H5O.
What is most valuable?
I am using calls functionality from DLP forwarding calls and SSL inspection in Barracuda CloudGen Firewall , and all of those are necessary to be used. I cannot qualify which is more important than others, but it is a complete product, and I am using all features.
What needs improvement?
I don't know about the centralized management console for managing policies in Barracuda CloudGen Firewall. We are not using it, and I don't know what that is. My vendor didn't provide me information about such a feature.
There are a lot of functionalities already present, but the problem is whether there is knowledge about the functionalities or stability.
Barracuda can make improvements for the next generation firewall product. In general, it is a very rare product in our market. More training and more learning for customers on how to use these products are needed. We are suffering from a lack of engineers in our market, so I am considering changing the product to a more popular one because it is not easy to recommend Barracuda, even this great product, but nobody uses it in Poland, and it is not easy to do anything. I know just one company which is supporting us.
Concerning the effectiveness of the filtering capabilities in Barracuda CloudGen Firewall, it happens sometimes that the classifications are misleading with wrong categorizations of what they use into the games or something into categories when it is definitely not in the category. I don't know from what reasons, but maybe it could be adjusted.
For how long have I used the solution?
I have been working with Barracuda CloudGen Firewall since 2016 in one location, and in the second one, it has been three years.
What do I think about the stability of the solution?
For stability, I would rate the next generation firewall stability of the product an eight.
What do I think about the scalability of the solution?
Regarding scalability and the ability to scale and expand with Barracuda CloudGen Firewall, there is no issue, so I would rate it a ten.
How are customer service and support?
I would rate the technical support for Barracuda CloudGen Firewall a six, as in the past, it was definitely better, but recently it has not been as good.
Which solution did I use previously and why did I switch?
I compared Barracuda CloudGen Firewall mainly with FortiGate.
How was the initial setup?
For the initial setup of Barracuda CloudGen Firewall, it was a bit more complex than simple; I would rate it at six on a scale from one to ten.
What about the implementation team?
I used a third-party company for the integration and setup of Barracuda CloudGen Firewall. I have some knowledge about the product and in-house capability, but I am relying on the third-party company for the purposes of integrations and new products.
Which other solutions did I evaluate?
The key reason I chose Barracuda over FortiGate is that I have been using Barracuda since 2016 or even 2015, and I am just used to it. It is stable, it is working, and there are no issues. However, to develop and use new features, I am lacking specialists, which is why it is not easy to expand with Barracuda CloudGen Firewall.
What other advice do I have?
I do not use the SD WAN capabilities of Barracuda CloudGen Firewall.
Threat protection feature in Barracuda CloudGen Firewall is working. I have not had much experience with other products, so I didn't support any issues with that module. It is working just fine.
I was a long-time strong fan of this product, but unfortunately, I will change the vendor for another one. Therefore, I cannot recommend it. If someone can set up things in-house with specialists, then it is quite a good product. There are not so many critical incidents, but probably mostly because it is not so popular. The pain point for me is support. In general, with a small scale, I was able to manage it myself, but with a wider scale, it is not possible to rely on in-house specialists, and there is no specialist available on the market. I would give this review an overall rating of seven.
Optimizes bandwidth with SD-WAN and threat protection but needs faster support and automation
How has it helped my organization?
Barracuda CloudGen Firewall SD-WAN capabilities have helped optimize our customers' bandwidth usage significantly because we are moving from MPLS to SD-WAN.
What is most valuable?
The most valuable features in Barracuda CloudGen Firewall are the functionality of DPI and IDS, ATP, and we also use it in an SD-WAN operation as well, so it works well in the SD-WAN feature.
In terms of our routing and VPN capabilities, Barracuda CloudGen Firewall performs well.
The threat protection features of Barracuda CloudGen Firewall are good, and I appreciate their reporting capabilities. It is a very good tool to have, especially when you are using IDS and IPS to block SQL injection, buffer overflow attacks, and similar threats in real-time.
We use the cloud centralized management console for managing security policies.
What needs improvement?
There is room for improvement in terms of response time and first-level support quality.
Barracuda CloudGen Firewall needs to learn from FortiManager and Palo Alto, as I see that they have automation and their reporting is easier to generate compared to Barracuda CloudGen Firewall.
I would like to see built-in endpoint integration in the next release of Barracuda CloudGen Firewall, including EDR. They need to improve or at least have an AI-assisted traffic analyzer alert. Their support can be improved as well.
What do I think about the stability of the solution?
We have not had any issues while integrating Barracuda CloudGen Firewall with third-party solutions because the professional support was really helpful with the integration.
How are customer service and support?
I rate the technical support by Barracuda a four out of ten.
How was the initial setup?
The initial setup for Barracuda CloudGen Firewall is quite easy.
What about the implementation team?
The integration of Barracuda CloudGen Firewall with other products is good because we required assistance and professional help from the Barracuda team to come and help us, which was beneficial.
We have not had any issues while integrating Barracuda CloudGen Firewall with third-party solutions because the professional support was really helpful with the process.
Which other solutions did I evaluate?
The pricing for Barracuda CloudGen Firewall is a bit pricey compared to Palo Alto or Fortinet.