
Overview
Fortinets WAF rulesets are based on the FortiWeb web application firewall security service signatures. These signatures are updated on a regular basis to include the latest threat intelligence from FortiGuard Labs.
In addition to protection against the OWASP Top 10, this ruleset has been optimized to defend against attacks that target the API attack surface. Your APIs touch your most critical data, and to protect that data you need specific protection for blocking API based attacks.
Designed for AWS WAF v2 For extended web application firewall features including ML based API discovery and protection, , you can try Fortinet FortiWeb Cloud WAF-as-a-Service, a SaaS service that requires no hardware or software deployed https://aws.amazon.com/marketplace/pp/Fortinet-Inc-Fortinet-FortiWeb-Cloud-WAF-as-a-Serv/B07PXMWJT1 .
Highlights
- Comprehensive protection for your API attack surface
- Regular updates from FortiGuard Labs
- Can be configured to log, alert and/or block
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/unit |
|---|---|
Charge per month in each available region (pro-rated by the hour) | $30.00 |
Charge per million requests in each available region | $1.80 |
Dimensions summary
Top-of-mind questions for buyers
Vendor refund policy
N/A
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Support offered by Fortinet. Contact Fortinet directly by email - awswaf@fortinet.com . Please see FAQ for more info.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Firewall protection has secured our customer portal and provides long-term peace of mind
What is our primary use case?
I use the solution as a firewall for our customer portal.
How has it helped my organization?
The solution provides peace of mind with website protection.
What is most valuable?
The solution offers IP Protection, which I find very valuable.
What needs improvement?
There is room for improvement in providing better access to updates, more seamless renewals, and the ability to rename objects.
For how long have I used the solution?
I have used the solution for 12 years.
Which solution did I use previously and why did I switch?
I did not use any previous solutions.
How was the initial setup?
Inital setup was fairly involved, requiring multiple sessions with Fortinet support.
What's my experience with pricing, setup cost, and licensing?
It is probably best to bring your own license (BYOL).
Which other solutions did I evaluate?
I did not consider any alternate solutions.
What other advice do I have?
The renewals are not seamless, and although updates are advertised via email from AWS, actual software updates require contacting support for access.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Intuitive and NIS2 Compliance with Fortinet WAF
Good baseline WAF protection for teams without a security engineer
2.No rule writing or tuning required to get OWASP Top 10 coverage FortiGuard Labs handles signature updates, so we're not chasing new CVEs
3.Stays native to AWS — same console, CloudWatch metrics, sampled logs, Terraform workflow
4.Rule groups are separable (OWASP, SQLi/XSS, bots, API), so we only pay for what we use
5.COUNT mode let us validate against real traffic before blocking Strong coverage-to-effort ratio for a small team with no dedicated WAF engineer
2.Documentation is lighter than Fortinet's on-prem WAF products; limited guidance on which rule group to pick for a given workload
2.FortiGuard handles signature updates, so new CVEs get covered faster than we could virtual-patch ourselves
3.Satisfies the WAF control for compliance and customer security questionnaires with something documented and defensible
