
Overview
The Barracuda CloudGen WAF detects all inbound web traffic and blocks SQL injections, cross-site scripting, malware uploads, volumetric & application DDoS, or any other attacks against your web applications. It also inspects the HTTP responses from the configured back-end servers for data loss prevention (DLP). The integrated access control engine enables administrators to create granular access control policies for Authentication, Authorization & Accounting (AAA), which gives organizations strong authentication and user control. The onboard L4/L7 load balancing capabilities enable organizations to quickly add back-end servers to scale deployments as they grow. Its application acceleration capabilities, including SSL offloading, caching, compression, and connection pooling, ensure faster application delivery of web application content. The Barracuda CloudGen WAF also supports autoscaling and bootstrapping.
NOTE: Only AMIs with version 10.x or higher version support the Elastic Network Adapters (ENA).
Highlights
- Detects and blocks SQL injections, cross-site scripting, malware uploads, volumetric & application DDoS, or any other attacks against your application. Authentication and access control gives organizations strong authentication and user control.
- Scans outbound traffic to detect sensitive data, and can either mask or block the information from being leaked out.
- Application acceleration capabilities, including caching, compression, and connection pooling for faster application delivery of web application content.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
t2.large Recommended | $1.318 |
m5.large | $1.318 |
m4.large | $1.318 |
t2.xlarge | $1.758 |
t3.xlarge | $1.758 |
c5.large | $1.318 |
c5.xlarge | $1.758 |
c4.large | $1.318 |
m3.medium | $1.038 |
c5.2xlarge | $2.996 |
Vendor refund policy
Terminate the instance at any time to stop incurring charges.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
- By default, the Barracuda Web Application Firewall web interface listens on HTTP/8000 and HTTPS/8443 ports so make sure these ports are added in the Inbound Rule of the security group which is associated with the Barracuda Web Application Firewall VM.
- Allow a few minutes before taking any further actions in the EC2 Portal after deploying the Barracuda Web Application Firewall. During this time the Barracuda Web Application Firewall is getting provisioned and licensed.
- Access the Barracuda Web Application Firewall using the associated Public IP/Public DNS with port 8000 over HTTP (i.e. http://<public IP>:8000)
- You will see the blue loading screen for some time and eventually you will be presented with the End User License Agreement (EULA).
- Click 'Accept' button and you will be redirected to the login page.
- Log in as 'admin' to begin configurations. Your initial password is the EC2 instance ID and can be changed later from Basic > Administration page.
For Deployment Guide and other instructions visit the Barracuda campus at https://campus.barracuda.com/product/webapplicationfirewall/article/WAF/AWS/
Support
Vendor support
Support Hours: Basic Support Hours: 8:00 AM - 5:00 PM PST, Monday through Friday.
Email and Phone Support offered 24x7 without any phone trees. You will actually speak to a live person. Please have your AWS Account ID available when you contact Barracuda Support; it is required for the support technican to assist you.
Support Phone Numbers: North America - 408 342 5300 Europe - +44 (0) 1256 300 102 Australia - +612 8019 7254 China - +86 400 720 8200 Japan - +81 3 5436 6236 India - +91 804 904 8600 Germany, Austria, Switzerland - +43 (0) 508 100 800
Support Website: https://www.barracuda.com/support
Support Email: support@barracuda.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Amazing Firewall Device
Strong web protection has improved global traffic quality and simplifies threat management
What is our primary use case?
The features from Barracuda were good, and we had detailed analytics and reports available, such as threat detections and traffic flows. Initially, it was challenging to set this up, but once we started using it, it became straightforward.
What is most valuable?
Barracuda WAF-as-a-Service offers excellent DDoS protection and really good content management. Barracuda WAF-as-a-Service has helped my organization positively by improving security. It saves time; initially, it took time to set this up because it was new and we had to learn a lot. It was not straightforward to implement, but once we understood the system, it became easy. The primary benefit is security, and the secondary benefit is time-saving. Cost-wise, it is reasonable—not too cheap and not too expensive.
What needs improvement?
For how long have I used the solution?
Which solution did I use previously and why did I switch?
What was our ROI?
What other advice do I have?
I purchased Barracuda WAF-as-a-Service through the AWS Marketplace . My advice for others who are thinking about using Barracuda WAF-as-a-Service is to proceed with it. It is a great product, especially in the cloud system. The procurement is easy with marketplace integration, and you can have your system directly deployed as an appliance, and it works effectively. My overall rating for this product is 8 out of 10. I want to emphasize making it easy for people to use and simple, as configuration is somewhat tricky.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Proactive web defenses have blocked attacks and keep critical applications consistently available
What is our primary use case?
During the last week, I used Barracuda WAF-as-a-Service to protect my web applications when we notified suspicious traffic patterns targeting login forms, as attackers were trying to inject SQL commands to bypass authentication and extract user data.
Barracuda WAF-as-a-Service simplified my day-to-day operations while keeping application risk low. For compliance reporting for different audits or normative requirements, I need logs and reports, and this solution prepared these reports easily and faster.
What is most valuable?
Barracuda WAF-as-a-Service has turned what used to be reactive firefighting into a proactive defense, and I prefer this technology as a service.
Barracuda WAF-as-a-Service has a positive impact in my organization by strengthening security, improving resilience, and reducing operational overhead. For example, it reduced downtime, as DDoS defense absorbed traffic surges during campaigns, keeping customer-facing apps online without disruption.
With Barracuda WAF-as-a-Service, downtime has dropped to near zero, even during a 300% traffic spike from a seasonal campaign. I reduced between one or two hours of downtime per quarter.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
I would rate Barracuda WAF-as-a-Service customer support as a nine on a scale of one to ten.
How was the initial setup?
What was our ROI?
Which other solutions did I evaluate?
What other advice do I have?
Regarding Barracuda WAF-as-a-Service's AI capabilities, governance and security are built with governance and security in mind, ensuring that automation is both trustworthy and compliant. Security safeguards exist because anomaly detection and AI monitor traffic patterns and flag suspicious behavior, helping catch credential stuffing and injection attempts early.
Barracuda WAF-as-a-Service's AI capabilities are generally accurate and reliable, especially in detecting OWASP Top 10 threats, bot attacks, and API misuse. Machine learning models continually retrain on the latest threat data, which helps maintain high detection accuracy and reduce false positives.
Barracuda WAF-as-a-Service is an excellent solution in the market. My overall review rating for Barracuda WAF-as-a-Service is eight out of ten.
Cloud protection has secured our web platforms and keeps sensitive data safe from attacks
What is our primary use case?
My main use case for Barracuda WAF-as-a-Service is web application and API protection. A specific example of how I use Barracuda WAF-as-a-Service for web application and API protection is that, similar to Amazon or eBay, I am using it for our social platforms as well. I am using it primarily for web protection.
What is most valuable?
The best features Barracuda WAF-as-a-Service offers include security, which is the main thing. I appreciate that you do not need to have hardware or an application on-premises, as you have everything on the cloud.
Having everything on the cloud makes things easier because there is no hardware on-premises. It is managed and patched by someone else, and I do not need to worry about patching and vulnerabilities. I also appreciate that it has DLP and all the advanced features that are needed.
Barracuda WAF-as-a-Service stops hackers from accessing my sensitive data and protects it from being exploited. The DLP and advanced features specifically provide this protection.
Barracuda WAF-as-a-Service has impacted my organization positively as it provides peace of mind through DLP features. Everything is on the cloud, so I am not worried about on-premises issues, power issues, or hardware issues. I have noticed specific outcomes or metrics such as faster response times and no downtime because it is on the cloud.
What needs improvement?
I think pricing could be improved regarding Barracuda WAF-as-a-Service. Otherwise, I have no other concerns about improvement.
For how long have I used the solution?
I have been using Barracuda WAF-as-a-Service for around three years.
What do I think about the stability of the solution?
The accuracy and reliability of output from Barracuda WAF-as-a-Service is consistent for me.
What do I think about the scalability of the solution?
Barracuda WAF-as-a-Service is deployed in my organization on public cloud.
What other advice do I have?
I rate Barracuda WAF-as-a-Service a nine out of ten. I chose nine out of ten because there is always space for improvement. I have no knowledge about Barracuda WAF-as-a-Service's governance and security regarding its AI capabilities. I purchased Barracuda WAF-as-a-Service through the AWS marketplace. My advice for others looking into using Barracuda WAF-as-a-Service is that it is easy to use and easy to deploy. I have no additional thoughts about Barracuda WAF-as-a-Service as it is all good from my end. I would rate this product a nine overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Improved web security has protected public apps from DDoS while support and cloud availability need work
What is our primary use case?
Our main use case for Barracuda WAF-as-a-Service with clients is to secure their environments, especially for DDoS attacks and security vulnerabilities that we have found. We implement those solutions, and for smaller clients, we also suggest they adopt Barracuda WAF-as-a-Service . It is cheaper compared to other products in the market, but at the same time, it provides sufficient capabilities so clients can get started.
A recent situation where I recommended Barracuda WAF-as-a-Service to a client involved a security breach because their firewall was a different model from a different vendor and was not able to handle the breach or address the security concerns. We then recommended they adopt Barracuda WAF-as-a-Service. After implementing that solution, we resolved many attacks. Attacks continued to occur, but this time Barracuda WAF-as-a-Service was able to stop them, scan them, and prevent DDoS and DLP attacks. It was a good addition to that environment.
What is most valuable?
The best features Barracuda WAF-as-a-Service offers, in my experience, include bot protection, DDoS, and DLP . DDoS and bot API features are good. DLP does the job, but I would say it is not very good, though it will do the job for you.
When I mention DDoS protection and DLP, I can tell you that these features protect our clients from active DDoS attacks because most of our clients are public companies and well-known companies. Regardless of what kind of firewall or solution is implemented, people keep trying to break in. We see active, almost constant bot and DDoS attacks happening on those environments. Barracuda WAF-as-a-Service has never failed us so far. It is good, and we have not seen any clients complaining that it is not doing its job, failing, freezing, or hanging. It is doing its job.
Barracuda WAF-as-a-Service has significantly improved security in our organization and for our clients because without it, it was always a challenge to see what is happening in the environment, protect against bot attacks, protect against DDoS and DLP attacks, and ensure web protection. After adding this solution, there was a significant improvement in security for that environment.
What needs improvement?
I think Barracuda WAF-as-a-Service can still do better on the DLP side. The DLP side is a little weak, and their SaaS-based model which they provide in Azure and AWS is not very good. If you compare the high availability and fault tolerance of these with other products, I think those other products have advantages. If Barracuda WAF-as-a-Service can improve on availability, especially in public cloud infrastructures, that would be beneficial.
They also need to improve their support. Their support team is not very technical and helpful, and they need to ensure they provide the right person for the right support, especially when a ticket is open. Technically, when someone opens a ticket, they have already completed basic troubleshooting. Barracuda WAF-as-a-Service needs to hire more skilled engineers.
For how long have I used the solution?
I have been using Barracuda WAF-as-a-Service for a couple of years, and multiple clients use it. We are an MSP, so we provide that solution.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Barracuda WAF-as-a-Service.
What was our ROI?
I have not seen a return on investment with Barracuda WAF-as-a-Service, but I can say it is good.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Barracuda WAF-as-a-Service is that it is good. The pricing is normal, and everything is normal, so it is good.
What other advice do I have?
I do not have anything else to add about how I use Barracuda WAF-as-a-Service or any other interesting scenarios I have seen with my clients. Everything is good regarding the features or how they compare to other solutions. I would say that Barracuda WAF-as-a-Service's accuracy and reliability of output is between 50 and 60 percent. I give this product a rating of 7.