Listing Thumbnail

    Fortinet Managed Rules for AWS WAF - SQLi/XSS

     Info
    Deployed on AWS
    The SQLi/XSS Rule Group provides the latest protection from the two primary web application attack types: SQL injection and Cross-site scripting.
    4.1

    Overview

    Play video

    Fortinet's WAF rulesets are based on the FortiWeb web application firewall security service signatures, and are updated on a regular basis to include the latest threat information from FortiGuard Labs. The SQLi/XSS Ruleset provides protection from the two primary web application attack types identified in the OWASP Top 10, SQL Injection and Cross-Site Scripting. Please see our other rulesets for additional protections.

    Highlights

    • Detects SQL Injection and Cross-Site Scripting Attacks
    • Can be configured to log, alert and/or block
    • Regular updates from FortiGuard Labs

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Fortinet Managed Rules for AWS WAF - SQLi/XSS

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $15.00
    Charge per million requests in each available region
    $1.00

    AI Insights

     Info

    Dimensions summary

    You pay for this product using two usage-based charges that combine on your bill. The first is a monthly charge that applies separately in each AWS region where you run the rules. This charge is pro-rated by the hour, so you only pay for the time used. The second charge scales with traffic: you pay per million requests processed in each region. Both charges apply per region, so costs grow as you add regions or handle more request volume. There is no upfront commitment; billing follows actual usage.

    Top-of-mind questions for buyers

    The request charge counts the web traffic that AWS WAF processes using these rules. One unit equals one million requests inspected in a given region. The rules pair with AWS WAF to check traffic against protections for the OWASP Top 10 web application threats, including SQL injection and cross-site scripting.
    Both charges apply at the same time and add together per region. The monthly charge is a fixed base for each region, pro-rated by the hour. The per-million-request charge scales with your traffic volume. High-traffic applications see the request charge grow, while low-traffic setups are led by the monthly fee.
    Both charges apply separately in each region where you run the rules. Adding a region adds another monthly charge for that region and another per-million-request charge for traffic processed there. The monthly charge is pro-rated by the hour, so a region added mid-month bills only for the hours used.
    www.fortinet.com
    Helpful?

    Vendor refund policy

    Non-Refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Support offered by Fortinet. Contact Fortinet directly by email - awswaf@fortinet.com . Please see FAQ for more info.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Threat Intelligence Updates
    Receives regular updates from FortiGuard Labs with latest threat information and security signatures
    Configurable Response Actions
    Supports configuration of multiple response actions including logging, alerting, and blocking of detected threats
    OWASP Top 10 Protection
    Provides protection against primary web application attack types identified in OWASP Top 10 standards
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Comprehensive protection against all OWASP Top 10 Web Application Threats
    Code Injection Prevention
    Managed rules targeting code injection techniques including SQLi, NoSQLi, and OS command injection
    Technology-Specific Vulnerability Protection
    Dedicated rules for known exploits in Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Malicious Bot Detection
    Malicious Bots rulesets included for bot-based threat mitigation
    OWASP Top 10 Attack Protection
    Provides protection against web attacks including SQL injection, cross-site scripting (XSS), command injection, NoSQL injection, path traversal, and predictable resource exploitation.
    Managed Rule Updates
    Rules are written, managed and regularly updated by F5's security specialists to ensure protection against evolving threats without requiring manual intervention.
    AWS WAF Integration
    Rules can be attached to AWS WAF instances for immediate deployment and protection enhancement.
    Automated Threat Detection
    Utilizes security expertise to identify and mitigate vulnerabilities that are part of the OWASP Top 10 attack vectors.
    Pay-as-You-Go Licensing Model
    Rules are licensed on a consumption-based pricing structure where usage determines costs.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.1
    27 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    30%
    63%
    7%
    0%
    0%
    10 AWS reviews
    |
    17 external reviews
    External reviews are from G2  and PeerSpot .
    Mohamed J.

    Managed Rules Feel Too Broad—False Positives and Limited Rule-Trigger Visibility

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best is the combination of **strong, continuously updated threat protection and ease of management**. Fortinet’s managed rules add protection against common web and API attacks, including OWASP Top 10 threats, SQL injection, XSS, known exploits, CVEs, and malicious bots, while the rules are regularly updated through FortiGuard Labs. This reduces the amount of time and effort required to maintain WAF rules manually.
    What do you dislike about the product?
    The main drawback is that managed rules can sometimes be **too broad or generate false positives**, requiring additional tuning and exclusions for specific applications. It would also be helpful to have more granular visibility into why a particular rule triggered and simpler customization options without increasing the management overhead.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF help reduce the effort required to protect our web applications and APIs from common threats such as SQL injection, XSS, and known exploits. The continuously updated rules reduce manual rule maintenance, improve our security coverage, and help our team respond to emerging threats more quickly while saving time on WAF management.
    Eddy Omar L.

    Ready-to-Use Security Rules That Simplify API Protection

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    It’s a library of preconfigured, ready-to-use signatures and rules that makes security protections extremely easy to deploy and maintain. These rules are updated regularly to ensure up-to-date security. To be specific they help to secure API from injection attacks (CSS. CEVs, etc)
    What do you dislike about the product?
    Rules can become complex to set up, and the UI doesn’t really help, which makes management and enrolling new personnel difficult. Also, these rules can only be applied to WAS apps/services.
    What problems is the product solving and how is that benefiting you?
    It helped us harden our API by applying a preconfigured OWASP Top 10 ruleset. As a result, we were able to align with security standards and best practices, making our API connections/integrations and management more secure. Also, performance was not impacted.
    Youcef E.

    Set-and-Forget Security with Auto-Updating Rules

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules for AWS WAF protects our web apps against OWASP Top 10 attacks, including SQL injection, XSS, and bot attacks. The managed rulesets save us from writing custom rules manually, and layering them with rate limiting and geo-blocking enhances security. I appreciate that it blocks attacks at the edge without the need for manual rule upkeep, and we no longer have to write and update signatures ourselves. The automatic handling of new CVEs allows our developers to stay focused on features while security remains current. I love the 'set and forget' threat protection with rules updating automatically, requiring zero manual patching. The initial setup was smooth, taking under 30 minutes and attaching to the ALB in the AWS console without needing any config files, and it worked out of the box.
    What do you dislike about the product?
    I occasionally experience false positives, where some legitimate traffic gets flagged, especially with multi-step web apps. Additionally, I feel the logging could be more granular. Another concern is the pricing, which jumps at certain request volume tiers.
    What problems is the product solving and how is that benefiting you?
    I use Fortinet Managed Rules for AWS WAF to protect web apps from attacks like SQL injection without manual rule upkeep. It saves time by auto-updating rules, allowing my team to focus on development while maintaining current security.
    Marketing and Advertising

    Reliable protection with minimal maintenance

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules provide strong, continuously updated protection against common web threats without requiring me to manually maintain a large set of WAF rules. The integration with AWS WAF is straightforward, and Fortinet’s threat intelligence makes it a good low-maintenance security layer.
    What do you dislike about the product?
    The main downside is the limited visibility and control compared with custom AWS WAF rules. Troubleshooting false positives can sometimes be difficult, and the documentation could provide more detail about exactly why specific requests are blocked.
    What problems is the product solving and how is that benefiting you?
    It helps protect our web applications from common attacks and malicious traffic without requiring us to build and maintain every WAF rule ourselves. This reduces the operational overhead for the team and gives us an additional security layer that is easy to integrate with our existing AWS infrastructure.
    Fairose Al Mahdhi

    Managed rules have strengthened web security and reduce manual protection effort for internal sites

    Reviewed on Jul 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Fortinet Managed Rules for AWS WAF is to protect our internal intranet sites and to publish some load as we are using it there.

    Regarding my main use case, ease of adoption, rule training, and cost model are vital because it is a managed rule group inside AWS WAF, meaning you do not get the FortiWeb full feature set. A learning-based positive security model without detailed app layer analytics and dashboarding means you need to make it there. When teams move to full FortiWeb cloud, they transition to self-managed FortiWeb.

    What is most valuable?

    The best features Fortinet Managed Rules for AWS WAF offers are real-time protection against OWASP Top Ten threats, FortiGuard threat intelligence, and automatic rule updates without manual maintenance, which leads to low false positives and easy integration with AWS WAF. What stands out most is the combination of continuously updated threat intelligence and managed protections, helping secure web applications with minimal operational effort.

    Fortinet Managed Rules for AWS WAF has positively impacted my organization by improving overall web application security by blocking common attacks such as SQL injections and XSS for traffic before they reach the application. It reduced the workload of the security team through automatic updates, improved compliance, and minimized the risk of downtime caused by web-based attacks. Overall, it strengthened our security posture while reducing operational effort.

    The automatic rule updates have reduced the operational effort for our team because we did not need to manually track new web vulnerabilities and update WAF signatures. For example, when new CVEs or emerging web attacks are released, Fortinet automatically updates the managed rule group, FortiGuard, which saves us time, ensures faster protection, and allows the team to focus on network operations instead of continuously tuning WAF rules.

    What needs improvement?

    Overall, Fortinet Managed Rules for AWS WAF is a solid solution, but it could be improved with more granular customization of managed rules, better visibility into why specific requests are blocked, more detailed reporting and analytics, and tighter integration with SIEM and SOAR platforms for incident response, which would add value. These improvements would make troubleshooting and security operations more efficient.

    Besides better rule customization and reporting, I would prefer to see a more intuitive management interface with easier policy tuning and clearer dashboards. Improved integration with third-party SIEM/SOAR and DevSecOps tools would streamline security operations. Faster support for newly discovered threats and more detailed documentation with deployment best practices would also help organizations adopt and manage the solution more effectively.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for seven years.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF is stable.

    What do I think about the scalability of the solution?

    The scalability of Fortinet Managed Rules for AWS WAF has been very good because it is built on AWS WAF, which scales automatically with application traffic without requiring additional infrastructure. As our traffic increased, we did not experience any major performance issues, and the managed rule continues to provide consistent protections. The automatic updates and cloud-native architecture made it easy to support growth with minimal operational effort.

    How are customer service and support?

    The customer support for Fortinet Managed Rules for AWS WAF is very good. Whenever we had an issue, they solved it immediately.

    Which solution did I use previously and why did I switch?

    Fortinet Managed Rules for AWS WAF is our first time using it with AWS WAF.

    What about the implementation team?

    I was not directly involved in the purchasing process of Fortinet Managed Rules for AWS WAF; the subscription was handled through our procurement cloud team. My role focused on deployment, configurations, and tuning the security aspects.

    What was our ROI?

    There is a positive return on investment because the managed rules reduced manual administration and improved protection against common attacks.

    When I mention reducing personnel, I mean my team spends less time managing web security now, not that we reduced the headcount. Since the managed rules are updated automatically, we spend less time creating and maintaining WAF rules manually, allowing the team to focus on higher value tasks such as security monitoring, incident response, and infrastructure improvements, which is helpful for our team to reduce spending.

    What's my experience with pricing, setup cost, and licensing?

    The pricing was reasonable considering the automatic updates, FortiGuard threat intelligence, and reduced operational effort.

    What other advice do I have?

    Overall, Fortinet Managed Rules for AWS WAF is a strong solution providing effective protection against common web threats while benefiting from FortiGuard threat intelligence and reduced operational effort through automatic rule updates.

    My advice to others looking into using Fortinet Managed Rules for AWS WAF is that we hardly open support cases. I would rate this solution an 8 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews