Skip to content
Notifications
Clear all

Imperva vs Barracuda for a Microsoft shop?

1 Posts
1 Users
0 Reactions
1 Views
(@davidn)
Estimable Member
Joined: 6 days ago
Posts: 56
Topic starter   [#14478]

We're currently evaluating a web application firewall (WAF) and DDoS mitigation solution for our environment, which is heavily invested in the Microsoft ecosystem. Our primary applications are ASP.NET-based, hosted on a mix of Azure App Services and on-premises IIS servers, with Microsoft SQL Server backends.

The shortlist has come down to Imperva and Barracuda. I've started a preliminary comparison spreadsheet focusing on integration and operational factors critical for a Microsoft shop, and I'd appreciate feedback on my initial findings and any blind spots.

Key considerations for us:

* **Native Integration:** How seamless is the setup with Azure Active Directory for admin access, Azure Monitor/Sentinel for logging, and Azure Key Vault for certificate management? Imperva's documentation suggests a more Azure-native posture, but I'm looking for real-world implementation experience.
* **Protocol Support:** We have several legacy SOAP/WCF services still in operation. I need to confirm the depth of support for these Microsoft-specific protocols, beyond standard HTTP/HTTPS inspection.
* **Configuration and Management:** The administrative overhead for tuning and false-positive reduction is a major concern. I'm particularly interested in how each platform handles the learning phase for complex .NET applications with dynamic query strings and ViewState.
* **Pricing Model Clarity:** Beyond the base subscription, we need to understand the cost implications for outbound data transfer from logs sent to our SIEM, API call volumes for automation scripts, and any per-rule or per-policy premiums.

My initial analysis suggests Imperva may have an edge in Azure integration and bot management sophistication, while Barracuda often highlights its granular control for custom applications and potentially simpler pricing. However, I lack detailed data on operational day-to-day management within a stack like ours.

Has anyone conducted a similar evaluation, specifically with a Microsoft-centric tech stack? I am most interested in:
- Comparative administrative effort for initial rule tuning and ongoing exception handling.
- Performance impact observations on ASP.NET session state and SQL query patterns.
- Any limitations encountered when integrating with Microsoft's cloud security tools.


Measure twice, buy once.


   
Quote